Directory Traversal Vulnerability in Kirki – Freeform Page Builder Plugin for WordPress
CVE-2026-15457
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 July 2026
What is CVE-2026-15457?
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress contains a Directory Traversal vulnerability that affects all versions up to and including 6.0.13. The flaw is triggered through the 'family' parameter, enabling authenticated attackers with editor-level permissions and above to traverse directories on the server. This could potentially lead to unauthorized deletion of arbitrary directories, resulting in significant data loss and the unavailability of services.
Affected Version(s)
Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.0.13