PT-2026-45693 · WordPress · Kirki

·

CVE-2026-8206

·

Published

2026-06-02

·

Updated

2026-06-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kirki versions 6.0.0 through 6.0.6
Description The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress contains a flaw allowing unauthenticated privilege escalation and account takeover. The issue occurs because the plugin accepts an arbitrary email address when a username is provided in a password reset request, enabling attackers to send a password reset link for any registered user, including administrators, to an email address they control. This is achieved through the handle forgot password() function at the forgot-password endpoint. Approximately 150,000 sites are estimated to be exposed, and the issue is being actively exploited in the wild.
Recommendations Update to version 6.0.7 or later.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8206

Affected Products

Kirki