Kirki – Freeform Page Builder, Website Builder & Customizer

Kirki – Freeform Page Builder, Website Builder & Customizer has 18 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; all 18 are fixed as of August 2026. Their average CVSS score is 6.5, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 6 high. 2026 was the busiest year with 18 disclosures.

The most common weakness is Missing Authorization, behind 5 of the records (28%). Other recurring categories include Cross-Site Scripting, Deserialization Of Untrusted Data.

Every one of the 18 issues recorded for Kirki – Freeform Page Builder, Website Builder & Customizer has a vendor fix available, so running the current release closes all known holes.

17 independent researchers contributed these findings, most of them (2) reported by VanTastic. Kirki – Freeform Page Builder, Website Builder & Customizer is installed on roughly 500,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891027.05.2014Today19.05.20266.5Kirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via 'kirki_wp_admin_get_apis' Action CVSS 6.5 · 19.05.20267.5Kirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP CVSS 7.5 · 19.05.202601.06.20269.8Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password' CVSS 9.8 · 01.06.202626.06.20266.4Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.0.11 - Authenticated (Subscriber+) Server-Side Request Forgery CVSS 6.4 · 26.06.202629.06.20267.2Kirki <= 6.0.11 - Unauthenticated Server-Side Request Forgery CVSS 7.2 · 29.06.20265.3Kirki <= 6.0.11 - Missing Authorization CVSS 5.3 · 29.06.20265.3Kirki <= 6.0.11 - Unauthenticated HTML Injection CVSS 5.3 · 29.06.202601.07.20265.3Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters CVSS 5.3 · 01.07.20265.3Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action CVSS 5.3 · 01.07.202606.07.20267.5Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.0.12 - Unauthenticated SQL Injection CVSS 7.5 · 06.07.20265.3Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Missing Authorization CVSS 5.3 · 06.07.20267.2Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.0.11 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 06.07.20268.1Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.0.12 - Unauthenticated PHP Object Injection CVSS 8.1 · 06.07.202616.07.20264.9Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter CVSS 4.9 · 16.07.202623.07.20265.3Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter CVSS 5.3 · 23.07.202631.07.20264.9Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip) CVSS 4.9 · 31.07.202604.08.20268.1Kirki – Freeform Page Builder, Website Builder & Customizer < 6.0.13 - Unauthenticated PHP Object Injection CVSS 8.1 · 04.08.202610.08.20266.4Kirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode CVSS 6.4 · 10.08.2026

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

18

Get automatic notifications for all Kirki – Freeform Page Builder, Website Builder & Customizer vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-8206

Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'

Read the full analysis

Vulnerability Records

18 records
2026-08-10 15:36CVE-2026-16974
6.4
Medium
Navapon Premkasem (71C4) (71C4)Yes
2026-08-04 00:00CVE-2026-12720
8.1
High
Jakub HermanYes
2026-07-31 19:48CVE-2026-15601
4.9
Medium
cuokonYes
2026-07-23 14:28CVE-2026-13464
5.3
Medium
Abu Hurayra (HurayraIIT)Yes
2026-07-16 14:41CVE-2026-15457
4.9
Medium
Wordfence PRISMYes
2026-07-06 00:00CVE-2026-57726
7.5
High
darooYes
2026-07-06 00:00CVE-2026-57727
5.3
Medium
Psalms Christopher Matovu (ByteOverride)Yes
2026-07-06 00:00CVE-2026-57725
7.2
High
VanTasticYes
2026-07-06 00:00CVE-2026-57724
8.1
High
VanTasticYes
2026-07-01 20:00CVE-2026-12122
5.3
Medium
Jagadesh AchantaYes
Showing 1–10 of 18 reports
Kirki – Freeform Page Builder, Website Builder & Customizer banner
Latestv6.2.2

Kirki – Freeform Page Builder, Website Builder & Customizer

Themeum

Author

Themeum

4.5(81)
90/100
Last Updated
2026-08-12 (3d ago)
Active Installs
500,000+
Downloads
14,944,663
Requires WP
5.9+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2014-05-27 (12y ago)

Kirki is a freeform visual builder for WordPress and an advanced theme customizer that lets you design and build complete websites visually — without coding. Unlike traditional page builders, Kirki uses an infinite freeform canvas, giving you full creative freedom without rigid grids or layout restrictions. Build landing pages, business websites, blogs, and full websites with responsive controls, dynamic content, and powerful design tools — all inside WordPress. Watch Kirki in action: 🔥 Why Choose Kirki? Kirki combines a modern visual builder with WordPress’s powerful customization system — so you can design freely without sacrificing flexibility. ✔ Freeform canvas — no rigid layouts or constraints ✔ Drag-and-drop visual editor with precise control ✔ Responsive editing for desktop, tablet, and mobile ✔ Built-in tools (forms, popups, dynamic content) ✔ Clean, performance-focused output ✔ Works with any WordPress theme ✔ Built for designers, developers, and teams 🧱 Core Features Visual Website Builder Design your website visually with full control. Freeform drag-and-drop editor Infinite canvas — no grid or column restrictions Real-time responsive editing (desktop, tablet, mobile) Pre-built components and layout blocks Global styles (colors, fonts, spacing) Version history and rollback Media manager for assets Light & dark mode interface ⚡ Dynamic Content & Smart Features Build scalable, data-driven websites. Dynamic content system (collections & templates) Conditional visibility controls Custom attributes for advanced control Developer-friendly extensibility Reusable design systems and components 🎨 Templates & Design Assets Start fast and customize everything. Ready-made website templates Pre-built sections and layout blocks Reusable design assets Import / export projects easily 🧩 Built-in Tools Everything you need — without extra plugins. Form builder with submission management Popup builder with visual controls Interaction and animation builder Icon library and media tools 🎬 Interactions & Animations Create engaging, modern experiences. Visual animation builder Interaction timeline editor Custom transitions and effects Text animation tools ⚙️ Advanced WordPress Customizer Extend WordPress customization with powerful controls. 35+ customizer controls Real-time preview Automatic CSS generation Conditional logic support Developer-friendly API Performance optimized 👥 Who Is Kirki For? Designers who want full creative freedom Freelancers building client websites Agencies managing multiple projects Developers extending WordPress functionality Anyone looking for a no-code visual builder for WordPress 🚀 What Makes Kirki Different? Kirki is not just another page builder. Instead of forcing layouts into rows and columns, Kirki gives you a freeform design experience — similar to modern design tools — while keeping the full power of WordPress. Design freely. Build with WordPress. Support Community support: https://facebook.com/groups/kirkicommunity Documentation: https://kirki.com/docs Website: https://kirki.com

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C