Hackers Exploit Kirki Flaw to Hijack WordPress Admin Accounts
TL;DR. A critical vulnerability (CVE-2026-8206) in the Kirki WordPress plugin allows hackers to take over admin accounts through password resets. - The flaw affects Kirki versions up to 6.0.6, impacting nearly 40% of its 500,000 active installations. - Attackers exploit a REST API endpoint that sends password reset links to arbitrary, attacker-controlled email addresses. - Urgent updates to version 6.0.7 are necessary to mitigate the ongoing active exploitation and prevent website compromise.
- Hackers are actively exploiting a privilege escalation vulnerability in the Kirki WordPress plugin.
- The flaw allows unauthenticated attackers to hijack user and administrator accounts.
- The vulnerability, CVE-2026-8206, stems from an exposed REST API endpoint sending password resets to arbitrary emails.
- Websites using Kirki versions 6.0.0 through 6.0.6 are affected, requiring an urgent update to version 6.0.7.
Sources
- Critical Kirki flaw exploited to hijack WordPress admin accounts — bleepingcomputer.com