Kirki WordPress Plugin Account Takeover (CVE-2026-8206): Unauthenticated Password Reset to Attacker-Controlled Email
A critical privilege escalation vulnerability in the Kirki — Freeform Page Builder plugin for WordPress, tracked as CVE-2026-8206, allows unauthenticated attackers to take over any … Read More