The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.
https://github.com/HackfutSecRoot/multi_exploit_wp
https://github.com/Dungsocool/CVE-2026-8206
https://github.com/kirstenruge-ship-it/cve-bench-harbor
https://github.com/nahamsec/wp-cve-intel
https://github.com/izxci/CVE-2026-8206
https://github.com/Jenderal92/CVE-2026-8206
https://github.com/O99099O/CVE-2026-8206-Poc-