Hackers Exploit Kirki Flaw to Hijack WordPress Admin Accounts

TL;DR. A critical vulnerability (CVE-2026-8206) in the Kirki WordPress plugin allows hackers to take over admin accounts through password resets. - The flaw affects Kirki versions up to 6.0.6, impacting nearly 40% of its 500,000 active installations. - Attackers exploit a REST API endpoint that sends password reset links to arbitrary, attacker-controlled email addresses. - Urgent updates to version 6.0.7 are necessary to mitigate the ongoing active exploitation and prevent website compromise.

Sources

Back to QLANKR News