CVE-2026-15601 | themeum Kirki Plugin up to 6.0.13 on WordPress Zip Extraction extract_zip_file src path traversal
A vulnerability, which was classified as critical, has been found in themeum Kirki Plugin up to 6.0.13 on WordPress. This affects the function extract_zip_file of the component Zip Extraction. The manipulation of the argument src leads to path traversal.
This vulnerability is documented as CVE-2026-15601. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More