> Critical Kirki flaw exploited to hijack WordPress admin accounts
[AUTHOR: Bill Toulas]
[DATE: 02/06/2026 22:12]
[LANGUAGE: EN]
Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]