WordPress Plugin Vulnerabilities

Kirki < 6.0.7 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP

Description

The plugin is vulnerable to arbitrary file read and deletion via the `downloadZIP` function due to insufficient file path validation and a missing capability check. This makes it possible for unauthenticated attackers to read and delete files within the WordPress uploads base directory.

Affects Plugins

Fixed in 6.0.7

References

Classification

Type
FILE DELETION
CWE

Miscellaneous

Original Researcher
Rafie Muhammad
Verified
No

Timeline

Publicly Published
2026-05-19 (about 3 months ago)
Added
2026-05-19 (about 3 months ago)
Last Updated
2026-05-19 (about 3 months ago)

Other