What is CVE-2026-17604?
This vulnerability affects the Kirki – Freeform Page Builder plugin for WordPress. It allows Directory Traversal via the 'data' parameter, enabling authenticated attackers with editor-level access and above to read sensitive files on the server. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu boşluq WordPress üçün Kirki – Freeform Page Builder plagininə təsir edir. 'data' parametri vasitəsilə Directory Traversal hücumuna imkan verir, editor və yuxarı səlahiyyətli istifadəçilərə serverdəki həssas faylları oxumağa şərait yaradır. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What level of user privilege is required to exploit CVE-2026-17604?
Exploiting this vulnerability requires an authenticated user with editor-level access and above.
Which plugin is affected by CVE-2026-17604 and how can it be mitigated?
This vulnerability affects the Kirki – Freeform Page Builder plugin for WordPress. It is recommended to update the plugin to the latest version for protection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.