Critical CVE-2026-8206 Flaw in Kirki Plugin Exposes 500,000 WordPress Sites to Attacks
ID: ac2445f0-81df-5cc4-90cf-873b2f9e03ba
STIX ID: report--ac2445f0-81df-5cc4-90cf-873b2f9e03ba
Feed Name: ThreatCluster
Threat Score
Critical CVE-2026-8206 in the Kirki WordPress plugin allows unauthenticated attackers to hijack user and admin accounts on over 500,000 sites (approximately 150,000 currently vulnerable); a patch (v6.0.7) was released on 2026-05-18 and site owners are urged to upgrade or disable the plugin immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
