Directory Traversal Vulnerability in Kirki – Freeform Page Builder Plugin for WordPress
CVE-2026-15457

4.9MEDIUM

What is CVE-2026-15457?

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress contains a Directory Traversal vulnerability that affects all versions up to and including 6.0.13. The flaw is triggered through the 'family' parameter, enabling authenticated attackers with editor-level permissions and above to traverse directories on the server. This could potentially lead to unauthorized deletion of arbitrary directories, resulting in significant data loss and the unavailability of services.

Affected Version(s)

Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.0.13

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PRISM
.