Friday 12 June 2026 06:45:58 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItalianoArabic

#CVE-2026-8206


When a Recovery Form Becomes a Break-In: The Kirki Plugin Bug That Put WordPress Sites at Risk

Published: 03 June 2026 17:16Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A critical flaw in a popular WordPress design plugin shows how a password-reset flow can turn from convenience feature into a remote account-seizure path.

Kirki Bug Turns a WordPress Customizer Into an Admin Takeover Risk

Published: 03 June 2026 02:07Category: Vulnerabilities & Patch ManagementGeo: Asia / BangladeshAuthor: DEEPAUDIT

A critical flaw in the Kirki WordPress plugin is being exploited in the wild, raising the stakes for sites where administrator access can reshape the entire control plane.