
CVE-2026-17604 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 … https://www.cve.org/CVERecord?id=CVE-2026-17604
Post summary
The Kirki plugin for WordPress is reported to be vulnerable to Directory Traversal in all versions up to 6.1.1, without details on patches, exploits, or PoC provided.
