Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Two critical vulnerabilities in the Kirki and Burst Statistics WordPress plugins allow unauthenticated attackers to escalate privileges and take over websites. Kirki versions 6. 0. 0 to 6. 0. 6 have a flaw in the password reset flow enabling attackers to reset passwords of high-privilege accounts by sending reset links to attacker-controlled emails. Burst Statistics versions 3. 4. 0 to 3. 4.
AI Analysis
Technical Summary
The Kirki WordPress plugin versions 6.0.0 through 6.0.6 suffer from an unauthenticated privilege escalation vulnerability (CVE-2026-8206, CVSS 9.8) due to a flawed password reset mechanism that allows attackers to specify a username and arbitrary email address to receive valid password reset links, enabling account takeover including administrative accounts. The Burst Statistics plugin versions 3.4.0 to 3.4.1.1 have an authentication bypass vulnerability in the application password validation logic of the REST API, which incorrectly authenticates attacker-supplied administrator credentials, allowing unauthorized access to admin-level REST API functions such as creating new admin accounts. Both vulnerabilities have been exploited in the wild, affecting hundreds of thousands of websites. Vendor patches are available and users are urged to update to Kirki 6.0.7 or newer and Burst Statistics 3.4.2 or newer.
Potential Impact
Successful exploitation of these vulnerabilities allows unauthenticated attackers to escalate privileges to administrator level and take full control of affected WordPress websites. This includes resetting passwords of high-privilege accounts in Kirki or impersonating administrators via the REST API in Burst Statistics, potentially leading to complete site takeover, unauthorized content modification, data theft, or use of the site for further attacks. Thousands of attacks have been detected and blocked recently, indicating active exploitation attempts.
Mitigation Recommendations
Official patches addressing these vulnerabilities have been released. Users should immediately update Kirki to version 6.0.7 or later and Burst Statistics to version 3.4.2 or later to remediate the security flaws. Applying these updates will prevent exploitation of the privilege escalation and authentication bypass issues. No additional mitigation steps are required beyond applying the vendor-provided fixes.
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Description
Two critical vulnerabilities in the Kirki and Burst Statistics WordPress plugins allow unauthenticated attackers to escalate privileges and take over websites. Kirki versions 6. 0. 0 to 6. 0. 6 have a flaw in the password reset flow enabling attackers to reset passwords of high-privilege accounts by sending reset links to attacker-controlled emails. Burst Statistics versions 3. 4. 0 to 3. 4.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Kirki WordPress plugin versions 6.0.0 through 6.0.6 suffer from an unauthenticated privilege escalation vulnerability (CVE-2026-8206, CVSS 9.8) due to a flawed password reset mechanism that allows attackers to specify a username and arbitrary email address to receive valid password reset links, enabling account takeover including administrative accounts. The Burst Statistics plugin versions 3.4.0 to 3.4.1.1 have an authentication bypass vulnerability in the application password validation logic of the REST API, which incorrectly authenticates attacker-supplied administrator credentials, allowing unauthorized access to admin-level REST API functions such as creating new admin accounts. Both vulnerabilities have been exploited in the wild, affecting hundreds of thousands of websites. Vendor patches are available and users are urged to update to Kirki 6.0.7 or newer and Burst Statistics 3.4.2 or newer.
Potential Impact
Successful exploitation of these vulnerabilities allows unauthenticated attackers to escalate privileges to administrator level and take full control of affected WordPress websites. This includes resetting passwords of high-privilege accounts in Kirki or impersonating administrators via the REST API in Burst Statistics, potentially leading to complete site takeover, unauthorized content modification, data theft, or use of the site for further attacks. Thousands of attacks have been detected and blocked recently, indicating active exploitation attempts.
Mitigation Recommendations
Official patches addressing these vulnerabilities have been released. Users should immediately update Kirki to version 6.0.7 or later and Burst Statistics to version 3.4.2 or later to remediate the security flaws. Applying these updates will prevent exploitation of the privilege escalation and authentication bypass issues. No additional mitigation steps are required beyond applying the vendor-provided fixes.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/kirki-burst-statistics-wordpress-plugin-flaws-in-attackers-crosshairs/","fetched":true,"fetchedAt":"2026-06-03T13:03:34.556Z","wordCount":1103}
Threat ID: 6a202626e29bf47b50b6e1fc
Added to database: 6/3/2026, 1:03:34 PM
Last enriched: 6/3/2026, 1:03:41 PM
Last updated: 6/3/2026, 2:09:05 PM
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.