Executive brief
Kirki is a popular WordPress framework used by developers to create rich customization options for themes. A security flaw in this plugin allows users with 'Editor' level permissions to delete arbitrary files from the web server. This could lead to a complete website failure or service outage if critical system files are removed.
Technical details
The Kirki plugin for WordPress (versions 6.0.13 and below) is vulnerable to arbitrary file deletion due to a path traversal flaw (CWE-22). The vulnerability exists because the application does not properly validate user-supplied input when handling file paths in the editor component. An attacker with Editor-level privileges (PR:H) can exploit this over the network without user interaction to delete files outside of the intended directory. This can lead to a denial-of-service condition by deleting core WordPress files or configuration data. The issue is addressed in version 6.0.14.
Affected products
- Themeum Kirki <= 6.0.13
Timeline
- 2026-06-23: other: Reported by researcher Ananda Dhakal
- 2026-07-27: disclosed: Vulnerability published by Patchstack
- 2026-07-27: patched: Fixed in version 6.0.14