Back to advisories

Critical Kirki flaw exploited to hijack WordPress admin accounts

Critical privilege escalation flaw in Kirki WordPress plugin (CVE-2026-8206) allows unauthenticated attackers to reset any user account including admins via an unvalidated REST API endpoint. Wordfence has already blocked 222+ exploitation attempts in 24 hours. Any WordPress site running Kirki versions up to 6.0.6 is actively at risk of full admin account compromise.

CRITICALAdvisoryJun 04, 2026
Action required
Immediately identify all WordPress instances running Kirki plugin and patch to version 6.0.7 or later. Search logs for POST requests to /wp-json/kirki* endpoints with password reset parameters and review password reset events for suspicious email redirects.
Affected products
Kirki - Freeform Page Builder, Website Builder & CustomizerDefiant (Wordfence)