


Perceptive Security
SOC/SIEM Consultancy

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions …
Published:
1 June 2026 at 22:00:00
Alert date:
2 June 2026 at 14:01:11
Source:
nvd.nist.gov
Web Technologies
The Kirki WordPress plugin versions 6.0.0 to 6.0.6 contains a critical privilege escalation vulnerability that allows account takeover. The vulnerability stems from the plugin accepting arbitrary email addresses during password reset requests when a username is provided. This flaw enables unauthenticated attackers to redirect password reset links for any registered user to their own email address, effectively allowing them to take over any account on the affected WordPress site. The vulnerability affects the Freeform Page Builder, Website Builder & Customizer plugin functionality.
Technical details
Mitigation steps:
Affected products:
Kirki WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-8206
https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L330
https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L48
https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/ElementGenerator.php#L227
https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L330
https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L48
https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/ElementGenerator.php#L227
https://plugins.trac.wordpress.org/changeset/3530843/kirki
https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
