[CIVN-2026-0286] Privilege Escalation Vulnerability in Kirki Plugin of WordPress

By Published On: June 3, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Privilege Escalation Vulnerability in Kirki Plugin of WordPress


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


WordPress Plugin – Kirki versions 6.0.0 through 6.0.6

Overview


A critical vulnerability has been reported in the Kirki plugin for WordPress that could allow an unauthenticated remote attacker to take over user accounts, including administrator accounts, on the targeted system.


Target Audience:

WordPress website owners, administrators, developers, and hosting providers using the Kirki plugin.


Risk Assessment:

Very high risk of account takeover, privilege escalation, unauthorized administrative access, and complete website compromise.


Impact Assessment:

Potential impact on confidentiality, integrity, and availability of the system.


Description


Kirki is an open-source framework for WordPress that provides Theme Customizer functionality and website-building capabilities.


A critical vulnerability exists in the Kirki plugin due to improper privilege management in its password reset functionality. The vulnerability arises because the plugin accepts an arbitrary email address when a username is supplied in a password reset request. As a result, an unauthenticated attacker can cause password reset links for legitimate users to be sent to attacker-controlled email addresses instead of the registered account owners email address.


Successful exploitation of this vulnerability could allow an attacker to gain elevated privileges on the targeted system.


Note: The vulnerability is being exploited in the wild.


Solution


Apply appropriate updates as mentioned by the vendor:

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki/kirki-600-606-unauthenticated-privilege-escalation-via-handle-forgot-password



Vendor Information


Kirki

https://wordpress.org/plugins/kirki/


References


Kirki

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki/kirki-600-606-unauthenticated-privilege-escalation-via-handle-forgot-password


CVE Name

CVE-2026-8206




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmogQfYACgkQ3jCgcSdc

ys/YURAAoGbnonGeSRb+FRMjrDMqU5c+5vM6J+8v+cHfn3bwVX0VCwL0SL1abq1P

65OfYf5F3MazqfTiMFwmcsoaAkZBa2gV/UtdQ6ZQ4vpAFiihjvThpTDFj5/wBrTy

dkKyPYqstXDWP+6D+JpdCNA3a3NUz92rRVtekkgz8kRj5N0ReSnT0tXe/jSkV10r

iriJ0miGDq6CEf1nqjOSBRGlH5HQpH3DgHdEniYdrIkdsKOEmm/TAT+GPJc/MqOT

apvL5aBqwfi2yYw7bcGj/R3m9yOy+CqR5+jqb2Z/XIpqF2JEwzgEGACaSfhCJ/fr

3tJxzNdMg/luVzTGkwO0wsEC2z92dpwzxRf6VcAHB0YO/DCEXGIR6fFTwaLeo96n

U33cHQycQaX+o2DkRd7xEmiXcxAxFDaHsYmlO+yAMj69K6NAMlu0b6272YRMrDg3

sr6IWQaL//syt7JEiX9tbKXscm16RpjXFF+OB9PI9qm0rJwVqt1vjsAJVZGmnA17

RdqL6CZkqeII8yTK8DosOVg6ubqrRuJp/YUbz/GWodAu7fiQIJE/841gdvi4g39U

8ufdzG6SQIh1A0LbMJQWfmLA6qCthryAzoFmJdma7uxewP7JFJINdtZZjRPMqy6D

UN0sYnF5FcXTEmdCwRaHFoc7GeqjFlmrRRyWGrhZ5gpnknDlze8=

=GOL9

—–END PGP SIGNATURE—–

Share this article