CVE Database /
CVE-2026-17604
CVE · Medium
CVE-2026-17604 — Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.2.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-17604
|
Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.2.0 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
4.9
|
< 6.2.0
|
6.2.0 |
2026-08-15 |
—
|
CVE-2026-17604
The Kirki plugin for WordPress contains a vulnerability that allows attackers with editor-level access or higher to read sensitive server files. This is due to a directory traversal issue in the plugin's handling of the 'data' parameter, which can be exploited by crafting a URL that bypasses the intended security check. As a result, attackers can access and potentially read sensitive information contained in arbitrary files on the server.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings