VYPR

Kirki – Freeform Page Builder, Website Builder & Customizer

by WordPress

CVEs (4)

  • CVE-2026-8206CriJun 2, 2026
    risk 0.57cvss 9.8epss 0.01

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the…

  • CVE-2026-16974MedAug 11, 2026
    risk 0.35cvss 6.4epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta Shortcode in all versions up to, and including, 6.2.0 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-17604MedAug 16, 2026
    risk 0.32cvss 4.9epss

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 via the 'data' parameter parameter. This makes it possible for authenticated attackers, with editor-level…

  • CVE-2026-15601MedAug 1, 2026
    risk 0.32cvss 4.9epss 0.01

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. This makes it possible for authenticated attackers, with custom-level…