:
[SECURITY]■ STORY TIMELINE

KIRKI PLUGIN FLAW LETS HACKERS HIJACK WORDPRESS ADMIN

A critical privilege escalation vulnerability in the popular Kirki WordPress plugin is being actively exploited to compromise administrator accounts. The flaw (CVE-2026-8206) allows attackers to take over any user account on affected sites.

2 SOURCESFIRST SEEN JUN 2, 10:12 PM► READ THE ARTICLE
Bleeping Computer+0m

Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress t…

Bleeping Computer+3d 15h

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets the…