
[CIVN-2026-0286] Privilege Escalation Vulnerability in Kirki Plugin of WordPress
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Privilege Escalation Vulnerability in Kirki Plugin of WordPress
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
WordPress Plugin – Kirki versions 6.0.0 through 6.0.6
Overview
A critical vulnerability has been reported in the Kirki plugin for WordPress that could allow an unauthenticated remote attacker to take over user accounts, including administrator accounts, on the targeted system.
Target Audience:
WordPress website owners, administrators, developers, and hosting providers using the Kirki plugin.
Risk Assessment:
Very high risk of account takeover, privilege escalation, unauthorized administrative access, and complete website compromise.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
Kirki is an open-source framework for WordPress that provides Theme Customizer functionality and website-building capabilities.
A critical vulnerability exists in the Kirki plugin due to improper privilege management in its password reset functionality. The vulnerability arises because the plugin accepts an arbitrary email address when a username is supplied in a password reset request. As a result, an unauthenticated attacker can cause password reset links for legitimate users to be sent to attacker-controlled email addresses instead of the registered account owners email address.
Successful exploitation of this vulnerability could allow an attacker to gain elevated privileges on the targeted system.
Note: The vulnerability is being exploited in the wild.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki/kirki-600-606-unauthenticated-privilege-escalation-via-handle-forgot-password
Vendor Information
Kirki
https://wordpress.org/plugins/kirki/
References
Kirki
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki/kirki-600-606-unauthenticated-privilege-escalation-via-handle-forgot-password
CVE Name
CVE-2026-8206
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmogQfYACgkQ3jCgcSdc
ys/YURAAoGbnonGeSRb+FRMjrDMqU5c+5vM6J+8v+cHfn3bwVX0VCwL0SL1abq1P
65OfYf5F3MazqfTiMFwmcsoaAkZBa2gV/UtdQ6ZQ4vpAFiihjvThpTDFj5/wBrTy
dkKyPYqstXDWP+6D+JpdCNA3a3NUz92rRVtekkgz8kRj5N0ReSnT0tXe/jSkV10r
iriJ0miGDq6CEf1nqjOSBRGlH5HQpH3DgHdEniYdrIkdsKOEmm/TAT+GPJc/MqOT
apvL5aBqwfi2yYw7bcGj/R3m9yOy+CqR5+jqb2Z/XIpqF2JEwzgEGACaSfhCJ/fr
3tJxzNdMg/luVzTGkwO0wsEC2z92dpwzxRf6VcAHB0YO/DCEXGIR6fFTwaLeo96n
U33cHQycQaX+o2DkRd7xEmiXcxAxFDaHsYmlO+yAMj69K6NAMlu0b6272YRMrDg3
sr6IWQaL//syt7JEiX9tbKXscm16RpjXFF+OB9PI9qm0rJwVqt1vjsAJVZGmnA17
RdqL6CZkqeII8yTK8DosOVg6ubqrRuJp/YUbz/GWodAu7fiQIJE/841gdvi4g39U
8ufdzG6SQIh1A0LbMJQWfmLA6qCthryAzoFmJdma7uxewP7JFJINdtZZjRPMqy6D
UN0sYnF5FcXTEmdCwRaHFoc7GeqjFlmrRRyWGrhZ5gpnknDlze8=
=GOL9
—–END PGP SIGNATURE—–


