Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs

0
Medium
Exploitweb
Published: Wed Jun 03 2026 (06/03/2026, 13:00:04 UTC)
Source: SecurityWeek

Description

Two critical vulnerabilities in the Kirki and Burst Statistics WordPress plugins allow unauthenticated attackers to escalate privileges and take over websites. Kirki versions 6. 0. 0 to 6. 0. 6 have a flaw in the password reset flow enabling attackers to reset passwords of high-privilege accounts by sending reset links to attacker-controlled emails. Burst Statistics versions 3. 4. 0 to 3. 4.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/03/2026, 13:03:41 UTC

Technical Analysis

The Kirki WordPress plugin versions 6.0.0 through 6.0.6 suffer from an unauthenticated privilege escalation vulnerability (CVE-2026-8206, CVSS 9.8) due to a flawed password reset mechanism that allows attackers to specify a username and arbitrary email address to receive valid password reset links, enabling account takeover including administrative accounts. The Burst Statistics plugin versions 3.4.0 to 3.4.1.1 have an authentication bypass vulnerability in the application password validation logic of the REST API, which incorrectly authenticates attacker-supplied administrator credentials, allowing unauthorized access to admin-level REST API functions such as creating new admin accounts. Both vulnerabilities have been exploited in the wild, affecting hundreds of thousands of websites. Vendor patches are available and users are urged to update to Kirki 6.0.7 or newer and Burst Statistics 3.4.2 or newer.

Potential Impact

Successful exploitation of these vulnerabilities allows unauthenticated attackers to escalate privileges to administrator level and take full control of affected WordPress websites. This includes resetting passwords of high-privilege accounts in Kirki or impersonating administrators via the REST API in Burst Statistics, potentially leading to complete site takeover, unauthorized content modification, data theft, or use of the site for further attacks. Thousands of attacks have been detected and blocked recently, indicating active exploitation attempts.

Mitigation Recommendations

Official patches addressing these vulnerabilities have been released. Users should immediately update Kirki to version 6.0.7 or later and Burst Statistics to version 3.4.2 or later to remediate the security flaws. Applying these updates will prevent exploitation of the privilege escalation and authentication bypass issues. No additional mitigation steps are required beyond applying the vendor-provided fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.securityweek.com/kirki-burst-statistics-wordpress-plugin-flaws-in-attackers-crosshairs/","fetched":true,"fetchedAt":"2026-06-03T13:03:34.556Z","wordCount":1103}

Threat ID: 6a202626e29bf47b50b6e1fc

Added to database: 6/3/2026, 1:03:34 PM

Last enriched: 6/3/2026, 1:03:41 PM

Last updated: 6/3/2026, 2:09:05 PM

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses