CVE-2026-8073: Kirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the 'downloadZIP' function in all versions up to, and including, 6.0.6. This makes it possible for unauthenticated attackers to read and delete arbitrary files limited in the WordPress uploads base directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kirki – Freeform Page Builder, Website Builder & Customizer (WordPress plugin)to a version that resolves this vulnerability.Fixed in 6.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8073?
CVE-2026-8073 has a high severity due to its potential for unauthenticated arbitrary file deletion.
How do I fix CVE-2026-8073?
To fix CVE-2026-8073, update the Kirki plugin to version 6.0.7 or later.
What products are affected by CVE-2026-8073?
CVE-2026-8073 affects versions of the Kirki plugin for WordPress up to and including 6.0.6.
What happens if I don't patch CVE-2026-8073?
If CVE-2026-8073 is not patched, attackers could exploit the vulnerability to delete arbitrary files on your server.
Is authentication required to exploit CVE-2026-8073?
No, CVE-2026-8073 can be exploited without authentication, making it critical to address.