CVE detail
CVE-2026-8206
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 4.6
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)Wordfence
6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password' 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-8206 Patch Status Patched Published Jun 1, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher CHOIGYEONGMIN More Details > Multiple ShapedPlugin Plugins Support Board Gravit
vendorwww.wordfence.comJun 11, 2026, 5:13 PM Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.
newswww.securityweek.comJun 3, 2026, 1:00 PM- https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJun 2, 2026, 4:17 AM - https://plugins.trac.wordpress.org/changeset/3530843/kirkiplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 2, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/ElementGenerator.php#L227plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 2, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L48plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 2, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L330plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 2, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/ElementGenerator.php#L227plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 2, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L48plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 2, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L330plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 2, 2026, 4:17 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.80 · max 1 stars
- amnsecurity/CVE-2026-8206-Kirki-WPMedium confidencegithubRepository topic discovery1 starsDiscovered Jul 16, 2026, 12:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-66399CVSS 8.5 · High
phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join p…
- CVE-2026-13152CVSS 8.1 · High
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key o…
- CVE-2026-12394CVSS 9.8 · Critical
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitr…
- CVE-2026-12502CVSS 8.4 · High
Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `supera…
- CVE-2026-16743CVSS 5.5 · Medium
A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the…
- CVE-2026-10610CVSS 8.5 · High
Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.