WordPress Plugin Vulnerabilities
Kirki < 6.0.7 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP
Description
The plugin is vulnerable to arbitrary file read and deletion via the `downloadZIP` function due to insufficient file path validation and a missing capability check. This makes it possible for unauthenticated attackers to read and delete files within the WordPress uploads base directory.
Affects Plugins
References
Classification
Type
FILE DELETION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Rafie Muhammad
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-05-19 (about 3 months ago)
Added
2026-05-19 (about 3 months ago)
Last Updated
2026-05-19 (about 3 months ago)