Skip to content

WordPress Plugin Vulnerability Exposes 500,000+ Websites to Privilege Escalation Attacks

Cybersecuritynews Abinaya June 3, 2026

A critical security flaw in the widely used Kirki WordPress plugin has exposed over 500,000 websites to potential account takeover attacks, with researchers warning that approximately 150,000 sites are actively vulnerable due to affected versions. Tracked as CVE-2026-8206 with a CVSS score of 9.8, the vulnerability impacts Kirki plugin versions 6.0.0 through 6.0.6. The issue […]

Extracted Entities