CVE-2026-8206
CVSS 9.8 CRITICAL: the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. EPSS 0.8% (54º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Kirki può fornire a un attacker un reset password valido per l’account di qualcun altro, quindi la destinazione dell’email diventa il trust boundary. Questo rompe la consueta assunzione che solo il vero owner possa ricevere un link di reset, e trasforma un singolo account esposto nel pieno controllo di WordPress una volta ottenuto l’accesso admin.
2 fonti · 3 giu
CVSS 9.8 CRITICAL: the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. EPSS 0.8% (54º percentile).
SecurityWeek
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.
originaleBleepingComputer
Critical Kirki flaw exploited to hijack WordPress admin accounts
Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators.
originalePart of the PlainSec briefing for 2026-06-03
Every edition of this story: La nuova release di Kirki mette a rischio gli account admin