CRITICALVulnerability
Global

Critical Kirki flaw exploited to hijack WordPress admin accounts

·Source: BleepingComputer

Updated:

Executive Summary

Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]

Analysis

Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]

Indicators of Compromise (1)

CVE (1)
CVE-2026-8206
Source Attribution

Originally published by BleepingComputer on Jun 2, 2026.

Related Threats