CVE-2026-8206
CVSS 9.8 CRITICAL: the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. EPSS 1% (68th percentile).
Vulnerabilities · 103 days ago
Kirki can hand an attacker a valid password reset for someone else’s account, so the email destination becomes the trust boundary. That breaks the usual assumption that only the real owner can receive a reset link, and it turns a single exposed account into full WordPress control once admin access is gained.
Wordfence says CVE-2026-8206 is being exploited in the wild and that it was introduced in Kirki 6.0.0, affecting versions 6.0.0 through 6.0.6. The plugin is active on more than 500,000 websites, and the reported impact includes malicious plugin installs, site content changes, web shells or backdoors, and access to private databases. Newly upgraded sites are in scope too, not just older installs.
CVSS 9.8 CRITICAL: the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. EPSS 1% (68th percentile).
2 sources covering this story
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.
Critical Kirki flaw exploited to hijack WordPress admin accounts
Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators.
Part of the PlainSec briefing for 2026-06-04