Hackers are actively exploiting a critical privilege escalation flaw in the Kirki plugin for WordPress that can let attackers take over any user account, including administrator accounts.

The vulnerability, tracked as CVE-2026-8206, was detected by WordPress security company Defiant. Wordfence’s firewall blocked more than 222 attack attempts targeting customers in the past 24 hours.

The affected plugin is officially called Kirki – Freeform Page Builder, Website Builder & Customizer. It is a freeform visual builder and advanced theme customizer used on more than 500,000 WordPress websites.

According to Wordfence, the issue was introduced in a recent major release, version 6.0.0, and affects all versions up to 6.0.6. Based on WordPress.org download statistics, those vulnerable versions are still being used by nearly 40 percent of the plugin’s user base.

The vulnerability is linked to a custom REST API endpoint used for password reset requests through the plugin’s handle_forgot_password() function. The problem comes from the plugin accepting any email address during the password reset process.

When an attacker provides a username, the plugin creates a valid password reset link for that account. However, instead of sending the link to the real account owner’s registered email address, it sends the reset link to an email address controlled by the attacker.

This makes it easy for unauthenticated attackers to generate password reset links for any registered user on a vulnerable website. If the targeted account belongs to an administrator, attackers can fully hijack the site.

READ
Europol Targets ‘The Com’ Network, Flags 4,340 URLs Linked to Violent Extremist Content

Once attackers gain admin access, they can install malicious plugins, change website content, upload web shells, create persistent backdoors, and access private database information.

The flaw was discovered by security researcher CHOIGYENGMIN, who reported it to Wordfence on May 4, 2026. Wordfence notified the plugin vendor on May 16, and a patched version, 6.0.7, was released on May 18, 2026.

Because CVE-2026-8206 is already being exploited and requires very little effort to abuse, website owners using Kirki should update to version 6.0.7 immediately or disable the plugin until they can safely patch it.


Buy ExpressVPN with PayPal or Credit Card

Advertisement