CVE · Medium

CVE-2026-15601 — Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15601 Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.1.0 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 6.1.0 6.1.0 2026-07-23

CVE-2026-15601

The Kirki plugin, used for page building and customization in WordPress, has a Path Traversal vulnerability affecting all versions up to 6.0.13 due to inadequate sanitization of user-supplied input in functions like extract_zip_file. Authenticated users with custom-level access can exploit this by downloading and extracting malicious ZIP files that contain path-traversing entries, potentially leading to remote code execution on the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.