admin account takeover

  1. CVE-2026-8206: Patch Kirki WordPress Privilege Escalation (Exploited)

    CVE-2026-8206 is a critical privilege-escalation flaw in the Kirki WordPress plugin, affecting versions 6.0.0 through 6.0.6, fixed in 6.0.7, and reported by BleepingComputer on June 2, 2026 as already being exploited to hijack administrator accounts. Site owners should update Kirki immediately...