Skip to content
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers' Crosshairs

Kirki, Burst Statistics WordPress Plugin Flaws in Attackers' Crosshairs

Ground.News June 3, 2026

A critical security flaw in the widely used Kirki WordPress plugin has exposed over 500,000 websites to potential account takeover attacks, with researchers warning that approximately 150,000 sites are actively vulnerable due to affected versions. Tracked as CVE-2026-8206 with a CVSS score of 9.8, the vulnerability impacts Kirki plugin versions 6.0.0 through 6.0.6. The issue allows unauthenticated attackers to escalate privileges by abusing a fl…

Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage