CVE-2026-8073
Kirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the 'downloadZIP' function in all versions up to, and including, 6.0.6. This makes it possible for unauthenticated attackers to read and delete arbitrary files limited in the WordPress uploads base directory.
| CWE | CWE-23 |
| Vendor | themeum |
| Product | kirki – freeform page builder, website builder & customizer |
| Published | May 19, 2026 |
| Last Updated | May 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for themeum kirki – freeform page builder, website builder & customizer
Be the first to know when new high vulnerabilities affecting themeum kirki – freeform page builder, website builder & customizer are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
themeum / Kirki – Freeform Page Builder, Website Builder & Customizer
0 ≤ 6.0.6
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/b073edd0-3f40-423e-976e-996b29caf66e?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.1/includes/API.php#L60 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3535640/kirki/trunk/includes/API.php
Credits
Rafie Muhammad