← WordPress Vulnerabilities
WordPress security by component

Kirki

Kirki is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: kirki

CVE-2026-65436: Kirki editors can delete arbitrary server files

Kirki through 6.0.13 lets an Editor supply a file target to an undisclosed deletion operation without adequate path confinement. The operation can delete a server file writable by PHP, causing data loss or site failure. The Patchstack CNA record does not disclose the endpoint, action, path parameter, deletion function or which filesystem locations are reachable.

PublishedJul 27, 2026
Known safe version6.0.14
Safe version
Jul 27, 2026 CVE-2026-65436
Kirki editors can delete arbitrary server files
Kirki through 6.0.13 lets an Editor supply a file target to an undisclosed deletion operation without adequate path confinement. The operation can delete a server file writable by PHP, causing data loss or site failure. The Patchstack CNA record does not disclose the endpoint, action, path parameter, deletion function or which filesystem locations are reachable.
6.0.14
CVE6.8
NVDPending
Jul 24, 2026 CVE-2026-13464
Kirki frontend previews expose nonpublic posts without authentication
An unauthenticated POST to /wp-json/kirki/v1/frontend/collection can select context type post and an arbitrary numeric post ID, then use attacker-controlled kirki_data blocks to render the target's title, content and excerpt. Vulnerable releases expose drafts, pending, private, password-protected and trashed posts because the route does not enforce read_post permission for nonpublic targets.
> 6.0.14
CVE5.3
NVDPending
Jul 20, 2026 CVE-2026-13147
Kirki: Server-side request forgery
Kirki is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is < 6.0.12.
6.0.12
CVE9.1
NVDPending
Jul 20, 2026 CVE-2026-12724
Kirki: A security weakness
Kirki is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 6.0.12.
6.0.12
CVE4.3
NVDPending
Jul 20, 2026 CVE-2026-12723
Kirki: A security weakness
Kirki is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 6.0.12.
6.0.12
CVE5.3
NVDPending
Jul 17, 2026 CVE-2026-15457
Kirki family parameter permits arbitrary directory deletion
Kirki 6.0.13 and earlier trusts a caller-controlled family value while handling font data. An authenticated editor can supply a traversal or absolute path and cause directories outside the intended font location to be deleted, creating a direct availability and data-loss risk.
> 6.0.13
CVE4.9
NVDPending
Jul 13, 2026 CVE-2026-57727
Kirki: A security weakness
Kirki is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.0.13.
> 6.0.13
CVE7.5
NVDPending
Jul 13, 2026 CVE-2026-57726
Kirki: SQL injection
Kirki is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 6.0.12.
6.0.13
CVE9.3
NVDPending
Jul 13, 2026 CVE-2026-57725
Kirki: Cross-site scripting
Kirki is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.0.11.
6.0.12
CVE7.1
NVDPending
Jul 13, 2026 CVE-2026-57724
Kirki: Code execution
Kirki is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 6.0.12.
6.0.13
CVE9.8
NVDPending
Jul 02, 2026 CVE-2026-57680
Kirki: A security weakness
Kirki is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.0.11.
6.0.12
CVE6.5
NVDPending
Jul 02, 2026 CVE-2026-12472
Kirki – Freeform Page Builder, Website Builder & Customizer: A security weakness
Kirki – Freeform Page Builder, Website Builder & Customizer is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.0.11.
> 6.0.11
CVE5.3
NVDPending
Jul 02, 2026 CVE-2026-12122
Kirki – Freeform Page Builder, Website Builder & Customizer: Sensitive information exposure
Kirki – Freeform Page Builder, Website Builder & Customizer is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 6.0.11.
> 6.0.11
CVE5.3
NVDPending
Jun 26, 2026 CVE-2026-57627
Kirki: Server-side request forgery
Kirki is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 6.0.11.
6.0.12
CVE4.9
NVDPending
Jun 02, 2026 CVE-2026-8206
Kirki – Freeform Page Builder, Website Builder & Customizer: Privilege escalation or authentication bypass
Kirki – Freeform Page Builder, Website Builder & Customizer is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is 6.0.0 through 6.0.6.
> 6.0.6
CVE9.8
NVDPending
May 19, 2026 CVE-2026-8096
Kirki – Freeform Page Builder, Website Builder & Customizer: A security weakness
Kirki – Freeform Page Builder, Website Builder & Customizer is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.0.6.
> 6.0.6
CVE6.5
NVDPending
May 19, 2026 CVE-2026-8073
Kirki – Freeform Page Builder, Website Builder & Customizer: Arbitrary file deletion
Kirki – Freeform Page Builder, Website Builder & Customizer is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 6.0.6.
> 6.0.6
CVE7.5
NVDPending