Kirki Themeum Kirki

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Themeum Kirki.

By the Year

In 2026 there have been 8 vulnerabilities in Themeum Kirki with an average score of 7.0 out of ten.

Year Vulnerabilities Average Score
2026 8 6.95

It may take a day or so for new Kirki vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Themeum Kirki Security Vulnerabilities

Kirki<=6.0.13 Arbitrary File Deletion via Editor
CVE-2026-65436 6.8 - Medium - July 27, 2026

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

Directory traversal

Kirki WP Plugin v6.0.14 IDOR via 'context' Param
CVE-2026-13464 5.3 - Medium - July 24, 2026

The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full title, content, and excerpt of any WordPress post including drafts, pending, privately published, password-protected, and trashed posts regardless of author, by supplying an arbitrary post ID via the context parameter alongside an attacker-controlled block template.

Insecure Direct Object Reference / IDOR

Kirki Freeform Dir Traversal <6.0.13
CVE-2026-15457 4.9 - Medium - July 17, 2026

The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability.

Directory traversal

Deserialization Vulnerability in Themeum Kirki <=6.0.12 (Object Injection)
CVE-2026-57724 9.8 - Critical - July 13, 2026

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

Marshaling, Unmarshaling

WordPress Kirki <=6.0.11 Stored XSS in kirki Component
CVE-2026-57725 7.1 - High - July 13, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.

XSS

Kirki <=6.0.12 Blind SQL Injection via Special Elements
CVE-2026-57726 9.3 - Critical - July 13, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.

SQL Injection

Missing AuthN in Themeum Kirki <=6.0.13
CVE-2026-57727 7.5 - High - July 13, 2026

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.

AuthZ

Kirki SSRF in v<=6.0.11
CVE-2026-57627 4.9 - Medium - June 26, 2026

Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

SSRF

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Themeum Kirki or by Themeum? Click the Watch button to subscribe.

Themeum
Vendor

Themeum Kirki
Product

subscribe