1.
aretiq.ai | research | | original ↗ | #appsec | #vulnerability-research | #account-takeover | #privilege-escalation
CVE-2026-8206: Kirki 6.0.0–6.0.6 sends WordPress password-reset links to an attacker-supplied email, enabling unauthenticated takeover of any account including admin; fixed in 6.0.7.
Skip to content