Vulnerability intelligence
CVE-2026-8206
A broken password reset mechanism in Kirki versions 6.0.0 through 6.0.6 lets unauthenticated attackers escalate privileges and take over WordPress admin accounts.
WordPress
2026
What WebPulse reported · 2 analyses
Kirki WordPress Plugin: CVSS 9.8 Flaw Exposes 500,000 Sites to Unauthenticated Takeover
A broken password reset mechanism in Kirki versions 6.0.0 through 6.0.6 lets unauthenticated attackers escalate privileges and take over WordPress admin account
June 18, 2026
June 2026: Six CVSS 9.8 Vulnerabilities. 1.14 Million WordPress Sites.
Six critical vulnerabilities actively exploited at the same time. 29,300+ attacks per day on one plugin alone. A premium plugin supply-chain compromised. The Wo
June 9, 2026
Related vulnerabilities