CVE-2026-8206
CVSS 9.8 CRITICAL: the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. EPSS 0.8% (54º percentile).
Vulnerabilità · 118 giorni fa
Kirki può fornire a un attacker un reset password valido per l’account di qualcun altro, quindi la destinazione dell’email diventa il trust boundary. Questo rompe la consueta assunzione che solo il vero owner possa ricevere un link di reset, e trasforma un singolo account esposto nel pieno controllo di WordPress una volta ottenuto l’accesso admin.
CVSS 9.8 CRITICAL: the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. EPSS 0.8% (54º percentile).
2 fonti che coprono questa storia
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.
Critical Kirki flaw exploited to hijack WordPress admin accounts
Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators.
Part of the PlainSec briefing for 2026-06-04