Directory Traversal Vulnerability in Kirki Page Builder Plugin for WordPress
CVE-2026-17604
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-17604?
The Kirki – Freeform Page Builder plugin for WordPress is susceptible to a directory traversal flaw that allows authenticated users with editor-level access or higher to read files from the server. This vulnerability arises from improper validation of the 'data' parameter, enabling attackers to bypass security measures intended to restrict access to files outside the uploads directory. By using a specially crafted URL containing the uploads base path along with directory traversal sequences (e.g., /wp-content/uploads/../../wp-config.php), malicious actors can expose sensitive information contained in the server’s files.
Affected Version(s)
Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.1.1