Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability.
Browse WordPress security risksQuick answer
Kirki – Freeform Page Builder, Website Builder & Customizer should be reviewed and updated if it matches the affected versions. The recommended fix is to apply the vendor-supported patched version or the mitigation steps below, then retest the public website with Fixnx.
Who is affected
Affected versions
- up to and including 6.0.13
Fixed versions
- 6.0.14
How to fix it
Kirki – Freeform Page Builder, Website Builder & Customizer is affected by CVE-2026-15457, an authenticated path traversal flaw that can delete arbitrary directories. An editor can escape the intended font path and remove site or server directories, causing data loss and downtime. Update Kirki – Freeform Page Builder, Website Builder & Customizer to 6.0.14 or a newer vendor-supported patched release. Prioritize exposed production systems and accounts that can reach the affected feature.
- Inventory every Kirki – Freeform Page Builder, Website Builder & Customizer deployment, version, exposed endpoint, environment, and owner.
- Confirm the installed release is not an affected version up to and including 6.0.13.
- Update Kirki – Freeform Page Builder, Website Builder & Customizer to 6.0.14 or a newer vendor-supported patched release.
- Until the update is complete, disable Kirki, revoke editor access to the affected action, and confirm a usable backup is ready.
- Review relevant logs and look for family values containing ../ or encoded traversal, missing directories or assets, and unusual editor activity.
- Restore deleted directories from a known-good backup and verify the integrity of WordPress core, themes, plugins, uploads, and server files.
- Clear WordPress, object, page, CDN, and browser caches, then update the asset inventory and close any temporary controls only after validation.
Scan now. Google sign-in is only needed to unlock fix guidance.
Verify the fix
- Confirm Kirki – Freeform Page Builder, Website Builder & Customizer is on the patched version or mitigation stated above and record the exact deployed version.
- Confirm traversal values are rejected and the affected action can delete only an approved font directory.
- Confirm the affected WordPress REST, AJAX, form, shortcode, upload, export, or admin feature is available only to the roles and requests that need it.
- Review logs after remediation for continued exploit attempts or signs that the issue was used before the fix.
- Rerun the relevant dependency, platform, vendor, or Fixnx security check and document the result, affected assets, change record, and cleanup evidence for CVE-2026-15457.
Related categories
Related security risks
More published guidance from the same primary category.
Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter
Updated July 24, 2026
mediumKirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action
Updated July 13, 2026
mediumKirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters
Updated July 13, 2026
Trusted references
FAQ
What is affected by CVE-2026-15457?
Kirki – Freeform Page Builder, Website Builder & Customizer versions listed as affected should be reviewed: up to and including 6.0.13.
What should I fix first?
Start with internet-facing sites, admin panels, login flows, plugins, themes, modules, packages, and systems that process user-controlled input or sensitive data.
How do I confirm the fix worked?
Apply the patched version or mitigation, clear caches where relevant, retest the affected workflow, and run a new Fixnx scan to verify public website exposure signals.
How are Fixnx security risk categories chosen?
Fixnx keeps one canonical risk page and assigns only broad, relevant categories such as ecosystem, technology area, or vulnerability class.
