This page may contain stale information. Last updated: 2026-06-03
Definition
Security risks from third-party WordPress plugins affecting millions of sites through privilege escalation and supply chain vulnerabilities.
Key Points
- CVE-2026-8206 in Kirki: unauthenticated admin takeover via password reset hijack
- 500K+ active Kirki installs; 40% on vulnerable 6.0.0-6.0.6
- Patch in 6.0.7; Wordfence blocked 222+ exploit attempts in 24h
- Plugin supply chain is high-value target for mass exploitation