Executive brief
The Kirki plugin for WordPress, which is used to build and customize websites, contains a security flaw that allows unauthorized individuals to access or delete files. This could lead to the loss of uploaded media, documents, or other site assets, potentially disrupting website operations and resulting in data loss. The issue affects all versions of the plugin up to 6.0.6.
Technical details
The Kirki plugin for WordPress is vulnerable to arbitrary file deletion and information disclosure due to a lack of capability checks and insufficient file path validation in the 'downloadZIP' function within the API.php component. An unauthenticated remote attacker can exploit this by sending crafted requests to manipulate file paths, allowing them to read or delete files within the WordPress uploads directory. This vulnerability is classified as a relative path traversal (CWE-23). The issue is present in all versions up to 6.0.6; users should update to a patched version if available.
Affected products
- Kirki Kirki – Freeform Page Builder, Website Builder & Customizer Up to, and including, 6.0.6
Timeline
- 2026-05-19: disclosed: Initial publication of the CVE record.
- 2026-05-19: advisory: Wordfence published the vulnerability details.