Directory Traversal Vulnerability in Kirki Page Builder Plugin for WordPress
CVE-2026-17604

4.9MEDIUM

What is CVE-2026-17604?

The Kirki – Freeform Page Builder plugin for WordPress is susceptible to a directory traversal flaw that allows authenticated users with editor-level access or higher to read files from the server. This vulnerability arises from improper validation of the 'data' parameter, enabling attackers to bypass security measures intended to restrict access to files outside the uploads directory. By using a specially crafted URL containing the uploads base path along with directory traversal sequences (e.g., /wp-content/uploads/../../wp-config.php), malicious actors can expose sensitive information contained in the server’s files.

Affected Version(s)

Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.1.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.