Kirki Themeum Kirki

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Themeum Kirki.

By the Year

In 2026 there have been 13 vulnerabilities in Themeum Kirki with an average score of 6.4 out of ten.

Year Vulnerabilities Average Score
2026 13 6.40

It may take a day or so for new Kirki vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Themeum Kirki Security Vulnerabilities

Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
CVE-2026-66629 7.1 - High - August 18, 2026

Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.

XSS

Kirki Freeform Page Builder 6.1.1 Auth Bypass
CVE-2026-18347 4.3 - Medium - August 16, 2026

The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read arbitrary user metadata and sensitive user record fields including email address, assigned roles, registration date, and any user_meta values belonging to any WordPress user including administrators, by supplying a target user ID with a user-type context to the frontend collection endpoint.

AuthZ

Kirki 6.1.1: DirTrav via data Param (Editor+)
CVE-2026-17604 4.9 - Medium - August 16, 2026

The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 via the 'data' parameter parameter. This makes it possible for authenticated attackers, with editor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The intended strpos()-based guard against leaving the uploads directory is bypassed by crafting a URL that includes the uploads base path as a substring while embedding directory traversal sequences, such as /wp-content/uploads/../../wp-config.php.

Directory traversal

Stored XSS in Kirki Freeform Page Builder <=6.2.0 via Shortcode
CVE-2026-16974 6.4 - Medium - August 11, 2026

The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta Shortcode in all versions up to, and including, 6.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Kirki Freeform Page Builder Path Traversal (Zip Slip) in v6.0.13
CVE-2026-15601 4.9 - Medium - August 01, 2026

The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. This makes it possible for authenticated attackers, with custom-level access and above, to write arbitrary files on the server, which can allow for remote code execution. The install_app, update_app, and get_kirki_template_from_zip code paths accept a user-supplied app src value to construct the download URL, and no sanitization is applied to prevent a crafted ZIP from being fetched and extracted with path-traversing entry names that escape the intended destination directory.

Directory traversal

Kirki<=6.0.13 Arbitrary File Deletion via Editor
CVE-2026-65436 6.8 - Medium - July 27, 2026

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

Directory traversal

Kirki WP Plugin v6.0.14 IDOR via 'context' Param
CVE-2026-13464 5.3 - Medium - July 24, 2026

The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full title, content, and excerpt of any WordPress post including drafts, pending, privately published, password-protected, and trashed posts regardless of author, by supplying an arbitrary post ID via the context parameter alongside an attacker-controlled block template.

Insecure Direct Object Reference / IDOR

Kirki Freeform Dir Traversal <6.0.13
CVE-2026-15457 4.9 - Medium - July 17, 2026

The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability.

Directory traversal

Deserialization Vulnerability in Themeum Kirki <=6.0.12 (Object Injection)
CVE-2026-57724 9.8 - Critical - July 13, 2026

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

Marshaling, Unmarshaling

WordPress Kirki <=6.0.11 Stored XSS in kirki Component
CVE-2026-57725 7.1 - High - July 13, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.

XSS

Kirki <=6.0.12 Blind SQL Injection via Special Elements
CVE-2026-57726 9.3 - Critical - July 13, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.

SQL Injection

Missing AuthN in Themeum Kirki <=6.0.13
CVE-2026-57727 7.5 - High - July 13, 2026

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.

AuthZ

Kirki SSRF in v<=6.0.11
CVE-2026-57627 4.9 - Medium - June 26, 2026

Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

SSRF

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Themeum Kirki or by Themeum? Click the Watch button to subscribe.

Themeum
Vendor

Themeum Kirki
Product

subscribe