Vulnerabilities · 103 days ago

New Kirki Release Put Admin Accounts at Risk

Kirki can hand an attacker a valid password reset for someone else’s account, so the email destination becomes the trust boundary. That breaks the usual assumption that only the real owner can receive a reset link, and it turns a single exposed account into full WordPress control once admin access is gained.

Wordfence says CVE-2026-8206 is being exploited in the wild and that it was introduced in Kirki 6.0.0, affecting versions 6.0.0 through 6.0.6. The plugin is active on more than 500,000 websites, and the reported impact includes malicious plugin installs, site content changes, web shells or backdoors, and access to private databases. Newly upgraded sites are in scope too, not just older installs.

CVE-2026-8206

NVD KEV

CVSS 9.8 CRITICAL: the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. EPSS 1% (68th percentile).

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-06-04

Editions

Related stories