Impact
The WordPress Kirki plugin, used for page building and customizer features, contains a directory traversal flaw that can be triggered by manipulating the "family" parameter. This flaw permits an authenticated user with editor-level access or higher to delete any directory located on the server hosting the WordPress site. The deletion can compromise critical data or foundational files, causing service disruption or loss of content.
Affected Systems
All releases of the Themeum Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress up to and including version 6.0.13 are vulnerable. Sites operating these versions expose editor or higher level users to the risk of arbitrary directory deletion.
Risk and Exploitability
The CVSS score of 4.9 places the issue in the moderate category, while an EPSS score of <1% indicates a low current priority for exploitation. It is not cataloged in CISA’s KEV list. Based on the description, it is inferred that the attacker must first obtain authenticated access with editor or higher rights, then craft a request that feeds a traversal string into the "family" parameter of the plugin’s REST API or Ajax endpoints; the server will then interpret the traversal and delete the targeted directory. Network access to the site’s API layer is required, and widespread remote exploitation is limited to environments that allow logged‑in users to reach these endpoints.
OpenCVE Enrichment