Kirki Plugin Critical Flaw: Unauthenticated Admin Account Takeover (CVE-2026-8206)

Introduction

A critical vulnerability in Kirki (Freeform Page Builder, Website Builder & Customizer), tracked as CVE-2026-8206 with a CVSS score of 9.8, lets an unauthenticated attacker hijack administrator accounts on affected sites. With over 500,000 active installations, researchers estimate roughly 150,000 sites remain exposed — and Wordfence has already logged hundreds of exploitation attempts.

The flaw is in the plugin’s handle_forgot_password() function: its custom REST API endpoint for password resets accepts an attacker-supplied email address instead of using the account’s actual registered email. In practice, that means an attacker can trigger a password reset for any user — including an admin — and have the reset link sent straight to their own inbox. Versions 6.0.0 through 6.0.6 are affected; the fix ships in 6.0.7.

What You Should Do Right Now

  1. Check if Kirki is installed under Plugins in wp-admin, and note the version number.
  2. Back up your site immediately before updating — active exploitation means some sites may already have been touched.
  3. Update to Kirki 6.0.7 or later right away.
  4. Check your admin user list for any account you don’t recognize, and review recent login activity if your security plugin tracks it.
  5. Force a password reset for all admin accounts as a precaution if the site was running an affected version for any length of time.

Why This Bug Is So Easy to Exploit

Most account-takeover vulnerabilities require some setup — guessing a username, social engineering, or chaining several bugs together. This one doesn’t. The attacker only needs a target site running a vulnerable Kirki version and a known (or guessable) admin username, which is often publicly visible via author archive pages. That’s why Wordfence’s attack telemetry climbed so fast after disclosure — it’s cheap and repeatable for attackers to automate.

FAQ

How do I know if my site was already compromised?
Check for administrator accounts you didn’t create, unexpected password reset emails in your inbox around the disclosure date, and any unfamiliar changes to site settings or content.

Is updating enough?
Updating closes the hole going forward. If you suspect prior exploitation, also reset all admin passwords and review the user list for anything added without your knowledge.

Does this affect the free or pro version of Kirki?
The vulnerability is in the core plugin’s password reset endpoint, so check your changelog against version 6.0.7 regardless of which edition you run.

Conclusion

An unauthenticated, no-special-conditions admin takeover on a plugin with 500,000+ installs is about as urgent as security alerts get. Update, then verify no one got there before you did.

Back up before every emergency update

Nota Backup & Restore keeps automatic, off-site backups and lets you recover even when wp-admin is down. Start your 14-day free trial — no credit card required.