CVE-2026-8206 — Themeum Kirki WordPress Plugin Password Reset Email Redirect Privilege Escalation
aretiq.ai | research | CVE-2026-8206 | #appsec | #vulnerability-research | #account-takeover | #privilege-escalation | #wordpress | #password-reset | #cve-2026-8206 | #kirki
Summary
CVE-2026-8206: Kirki 6.0.0–6.0.6 sends WordPress password-reset links to an attacker-supplied email, enabling unauthenticated takeover of any account including admin; fixed in 6.0.7.
- CVE
- CVE-2026-8206
- Published
- Collected
Skip to content