Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. The post Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs appeared first on SecurityWeek .
AI Analysis
Technical Summary
The Kirki WordPress plugin versions 6.0.0 through 6.0.6 suffer from an unauthenticated privilege escalation vulnerability (CVE-2026-8206, CVSS 9.8) due to a flawed password reset mechanism that allows attackers to specify a username and arbitrary email address to receive valid password reset links, enabling account takeover including administrative accounts. The Burst Statistics plugin versions 3.4.0 to 3.4.1.1 have an authentication bypass vulnerability in the application password validation logic of the REST API, which incorrectly authenticates attacker-supplied administrator credentials, allowing unauthorized access to admin-level REST API functions such as creating new admin accounts. Both vulnerabilities have been exploited in the wild, affecting hundreds of thousands of websites. Vendor patches are available and users are urged to update to Kirki 6.0.7 or newer and Burst Statistics 3.4.2 or newer.
Potential Impact
Successful exploitation of these vulnerabilities allows unauthenticated attackers to escalate privileges to administrator level and take full control of affected WordPress websites. This includes resetting passwords of high-privilege accounts in Kirki or impersonating administrators via the REST API in Burst Statistics, potentially leading to complete site takeover, unauthorized content modification, data theft, or use of the site for further attacks. Thousands of attacks have been detected and blocked recently, indicating active exploitation attempts.
Mitigation Recommendations
Official patches addressing these vulnerabilities have been released. Users should immediately update Kirki to version 6.0.7 or later and Burst Statistics to version 3.4.2 or later to remediate the security flaws. Applying these updates will prevent exploitation of the privilege escalation and authentication bypass issues. No additional mitigation steps are required beyond applying the vendor-provided fixes.
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Description
Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. The post Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Kirki WordPress plugin versions 6.0.0 through 6.0.6 suffer from an unauthenticated privilege escalation vulnerability (CVE-2026-8206, CVSS 9.8) due to a flawed password reset mechanism that allows attackers to specify a username and arbitrary email address to receive valid password reset links, enabling account takeover including administrative accounts. The Burst Statistics plugin versions 3.4.0 to 3.4.1.1 have an authentication bypass vulnerability in the application password validation logic of the REST API, which incorrectly authenticates attacker-supplied administrator credentials, allowing unauthorized access to admin-level REST API functions such as creating new admin accounts. Both vulnerabilities have been exploited in the wild, affecting hundreds of thousands of websites. Vendor patches are available and users are urged to update to Kirki 6.0.7 or newer and Burst Statistics 3.4.2 or newer.
Potential Impact
Successful exploitation of these vulnerabilities allows unauthenticated attackers to escalate privileges to administrator level and take full control of affected WordPress websites. This includes resetting passwords of high-privilege accounts in Kirki or impersonating administrators via the REST API in Burst Statistics, potentially leading to complete site takeover, unauthorized content modification, data theft, or use of the site for further attacks. Thousands of attacks have been detected and blocked recently, indicating active exploitation attempts.
Mitigation Recommendations
Official patches addressing these vulnerabilities have been released. Users should immediately update Kirki to version 6.0.7 or later and Burst Statistics to version 3.4.2 or later to remediate the security flaws. Applying these updates will prevent exploitation of the privilege escalation and authentication bypass issues. No additional mitigation steps are required beyond applying the vendor-provided fixes.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/kirki-burst-statistics-wordpress-plugin-flaws-in-attackers-crosshairs/","fetched":true,"fetchedAt":"2026-06-03T13:03:34.556Z","wordCount":1103}
Threat ID: 6a202626e29bf47b50b6e1fc
Added to database: 06/03/2026, 13:03:34 UTC
Last enriched: 06/03/2026, 13:03:41 UTC
Last updated: 07/30/2026, 12:55:37 UTC
Views: 109
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.