logo

Critical CVE-2026-8206 Flaw in Kirki Plugin Exposes 500,000 WordPress Sites to Attacks

ID: ac2445f0-81df-5cc4-90cf-873b2f9e03ba

STIX ID: report--ac2445f0-81df-5cc4-90cf-873b2f9e03ba

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-03

Date Updated: 2026-06-08

...
...

Critical CVE-2026-8206 in the Kirki WordPress plugin allows unauthenticated attackers to hijack user and admin accounts on over 500,000 sites (approximately 150,000 currently vulnerable); a patch (v6.0.7) was released on 2026-05-18 and site owners are urged to upgrade or disable the plugin immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.