PT-2026-45693 · WordPress · Kirki
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kirki versions 6.0.0 through 6.0.6
Description
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress contains a flaw allowing unauthenticated privilege escalation and account takeover. The issue occurs because the plugin accepts an arbitrary email address when a username is provided in a password reset request, enabling attackers to send a password reset link for any registered user, including administrators, to an email address they control. This is achieved through the
handle forgot password() function at the forgot-password endpoint. Approximately 150,000 sites are estimated to be exposed, and the issue is being actively exploited in the wild.Recommendations
Update to version 6.0.7 or later.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kirki