logo

Critical CVE-2026-8206 Flaw in Kirki Plugin Exposes 500,000 WordPress Sites to Attacks

ID: 4f0ea148-eb52-5b83-9f1f-3d02ad4f4ab2

STIX ID: report--4f0ea148-eb52-5b83-9f1f-3d02ad4f4ab2

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-03

Date Updated: 2026-06-04

...
...

**Critical Kirki plugin vulnerability (CVE-2026-8206) enables unauthenticated account hijacks and site takeover via a misconfigured password reset REST endpoint; affects Kirki 6.0.0–6.0.6 (≈500,000 sites, ~150,000 actively vulnerable), carries a CVSS 9.8, and was patched in version 6.0.7 on 2026-05-18 — administrators should update or disable the plugin and monitor for suspicious password-reset activity.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.