This page may contain stale information. Last updated: 2026-06-03

Definition

Security risks from third-party WordPress plugins affecting millions of sites through privilege escalation and supply chain vulnerabilities.

Key Points

  • CVE-2026-8206 in Kirki: unauthenticated admin takeover via password reset hijack
  • 500K+ active Kirki installs; 40% on vulnerable 6.0.0-6.0.6
  • Patch in 6.0.7; Wordfence blocked 222+ exploit attempts in 24h
  • Plugin supply chain is high-value target for mass exploitation

Sources