logo

Critical Kirki flaw exploited to hijack WordPress admin accounts

ID: a3dbdb3e-6a94-58cb-81ee-65ad24742482

STIX ID: report--a3dbdb3e-6a94-58cb-81ee-65ad24742482

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

Author: Bill Toulas

...
...

A critical vulnerability (CVE-2026-8206) in the Kirki WordPress plugin allowed attackers to request password resets for any user and have the reset links sent to an attacker-controlled email, enabling trivial account hijacking including administrators; Wordfence observed active exploitation and blocked multiple attempts, the issue impacts versions up to 6.0.6 (affecting a large portion of the plugin's userbase), and a patch was released in version 6.0.7 — site owners should upgrade or disable the plugin immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.