What it is
CVE-2026-8206 is an unauthenticated vulnerability affecting themeum Kirki – Freeform Page Builder, Website Builder & Customizer. The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is...
Vulnerability report
Kirki – Freeform Page Builder Privilege Escalation
themeum / Kirki – Freeform Page Builder · 6.0.0 to <= 6.0.6
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-8206 is an unauthenticated vulnerability affecting themeum Kirki – Freeform Page Builder, Website Builder & Customizer. The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is...
Is it exploited?
Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is high.
Who is affected?
themeum / Kirki – Freeform Page Builder 6.0.0 to <= 6.0.6.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request.
This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
BleepingComputer
Independent exploitation attestation added to the KEV Intelligence record.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| BleepingComputer First | 2026-06-03 08:20 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
No scanner integrations recorded yet.
No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.3%
Recent mention · BleepingComputer
Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]
Read full advisoryTimeline
High-confidence, third-party attested exploitation
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-8206
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-8206",
"confidence": "High",
"cvss_score": 9.8,
"cvss_estimated": false,
"epss_score": 0.0126,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.