Junglewise Threat Intelligence

CVE-2026-8206: Kirki Freeform Page Builder privilege escalation via account takeover

CVE-2026-8206 · Severity: critical · CVSS 9.8 · Published 2026-06-02

Executive brief

The Kirki plugin for WordPress, used for building and customizing websites, contains a critical security flaw that allows unauthorized individuals to take over any user account. By exploiting a weakness in the password reset process, an attacker can redirect reset links to their own email address. This could lead to a complete site takeover if an administrator's account is targeted, resulting in data theft or website defacement.

Technical details

The Kirki plugin for WordPress (versions 6.0.0 to 6.0.6) is vulnerable to an account takeover flaw classified as Improper Privilege Management (CWE-269). The vulnerability exists in the password reset logic within the ComponentLibrary controller, specifically where the plugin accepts an arbitrary email address when a valid username is provided in a reset request. An unauthenticated remote attacker can exploit this by initiating a password reset for a target user (such as an administrator) and specifying an attacker-controlled email address to receive the reset token. This allows the attacker to reset the password and gain full access to the account. A patch has been released in the plugin's changeset 3530843.

Affected products

  • Kirki Kirki – Freeform Page Builder, Website Builder & Customizer 6.0.0 - 6.0.6

Timeline

  • 2026-06-02: disclosed: CVE published by Wordfence and NVD

References

Related threats