Skip to content
Vulnerability intelligence

CVE-2026-8206 — WordPress Vulnerability

CVE-2026-8206. CVSS 9.8. The Kirki page builder plugin's password reset mechanism lets attackers take over administrator accounts. 150,000 sites running the vulnerable version right now.

CVSS 9.8 WordPress 2026