CVSS 9.8 privilege escalation in Kirki 6.0.0-6.0.6. Unauthenticated password reset to attacker email via handle_forgot_password REST endpoint.