Release Note

See what's new & improved

v2.5.2

05 Dec 2025

Kirki v2.5.2

Bug fixes:

Arbitrary File Upload vulnerability restricted to authenticated content-access users (CVE-2025-5831)

Missing authorization for multiple actions requiring the authenticated full-access role (CVE-2025-5835)

Unauthenticated Arbitrary File Download/Deletion vulnerability (CVE-2024-43955)

Settings change required full-access user roles (CVE-2024-43954)

Our website uses cookies to improve your browsing experience on our website. By continuing to use this website, you agree to their use. For details, please check our Privacy Policy.