PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15601 themeum CVE debrief

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. This makes it possible for authenticated attackers, with custom-level access and above, to write arbitrary files on the server, potentially leading to remote code execution. The install_app, update_app, and get_kirki_template_from_zip code paths accept a user-supplied app src value to construct the download URL, and no sanitization is applied to prevent a crafted ZIP from being fetched and extracted with path-traversing entry names that escape the intended destination directory. Evidence limits suggest that defenders verify installed plugin versions, restrict custom-level access, and monitor for suspicious file writes and API activity. Limited information available on affected scope and vendor remediation.

Vendor
themeum
Product
Kirki – Freeform Page Builder, Website Builder & Customizer
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-01
Original CVE updated
2026-08-01
Advisory published
2026-08-01
Advisory updated
2026-08-01

Who should care

WordPress administrators and users with custom-level access, security teams monitoring for suspicious file writes and API activity, and operators managing WordPress deployments should be aware of this vulnerability. They should verify installed plugin versions, restrict custom-level access, and monitor for suspicious activity to prevent potential remote code execution. Additionally, platform administrators and vulnerability management teams should prioritize patching or mitigating this vulnerability to prevent exploitation. Security teams should review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Affected product deployments should be identified in managed environments, and an owner should be assigned for follow-up. Official advisories or CVE records should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Monitoring, detection, and logs should be checked for exposed assets that need extra review. The CVE record was published on 2026-08-01T09:16:59.173Z and has not been modified since then. Evidence limits suggest that defenders verify installed plugin versions, restrict custom-level access, and monitor for suspicious file writes and API activity. Limited information available on affected scope and vendor remediation. The CVE record was published on 2026-08-01T09:16:59.173Z and has not been modified since then. Evidence limits suggest that defenders verify installed plugin versions, restrict custom-level access, and monitor for suspicious file writes and API activity. Limited information available on affected scope and vendor remediation. The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. Limited information available on affected scope and vendor remediation. The CVE record was published on 2026-08-01T09:16:59.173Z and has not been

Technical summary

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. This makes it possible for authenticated attackers, with custom-level access and above, to write arbitrary files on the server, potentially leading to remote code execution. The install_app, update_app, and get_kirki_template_from_zip code paths accept a user-supplied app src value to construct the download URL, and no sanitization is applied to prevent a crafted ZIP from being fetched and extracted with path-traversing entry names that escape the intended destination directory.

Defensive priority

Authenticated attackers with custom-level access can write arbitrary files on the server, potentially leading to remote code execution.

Recommended defensive actions

  • Inventory and verify installed plugin versions
  • Restrict custom-level access and above
  • Monitor for suspicious file writes and API activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. Limited information available on affected scope and vendor remediation. The CVE record was published on 2026-08-01T09:16:59.173Z and has not been modified since then. Evidence limits suggest that defenders verify installed plugin versions, restrict custom-level access, and monitor for suspicious file writes and API activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:16:59.173Z and has not been modified since then.