Vulnerability intelligence
CVE-2026-8206 — WordPress Vulnerability
CVE-2026-8206. CVSS 9.8. The Kirki page builder plugin's password reset mechanism lets attackers take over administrator accounts. 150,000 sites running the vulnerable version right now.
What WebPulse reported · 3 analyses
Kirki Plugin: 500,000 WordPress Sites Exposed to Admin Account Takeover via Password Reset
CVE-2026-8206. CVSS 9.8. The Kirki page builder plugin's password reset mechanism lets attackers take over administrator accounts. 150,000 sites running the vul
June 13, 2026
Avada Builder: WordPress's #1 Premium Theme Has an Unauthenticated SQL Injection
CVE-2026-4798. CVSS 7.5. The best-selling WordPress theme of all time — 700,000+ sales — lets unauthenticated attackers extract hashed passwords from the databa
June 13, 2026
June 2026: Six CVSS 9.8 Vulnerabilities. 1.14 Million WordPress Sites.
Six critical vulnerabilities actively exploited at the same time. 29,300+ attacks per day on one plugin alone. A premium plugin supply-chain compromised. The Wo
June 9, 2026
Related vulnerabilities