{"cve":"CVE-2026-8206","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[6.0.0,6.0.6]"}}],"enrichment":{"confidence":100.0,"confidence_source":"matching","scores":[{"score":100.0,"source":"matching"}]},"original":{"product":"Kirki – Freeform Page Builder, Website Builder & Customizer","source":"cna","vendor":"themeum"},"product":"kirki_–_freeform_page_builder,_website_builder_&_customizer","vendor":"themeum"},{"configurations":[{"platform":null,"status":"unaffected","versions":null}],"enrichment":{"confidence":80.0,"confidence_source":"inferred","scores":[{"score":80.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"product":"wordpress","vendor":"wordpress"}],"created":"2026-06-02T04:45:45.299659+00:00","updated":"2026-06-02T05:30:36.233388+00:00","vendors":["themeum","themeum$PRODUCT$kirki_–_freeform_page_builder,_website_builder_&_customizer","wordpress","wordpress$PRODUCT$wordpress"]},"epss":{"score":0.00772},"mitre":{"cpes":[],"created":"2026-06-02T03:28:49.326000+00:00","description":"The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/8xxx/CVE-2026-8206.json","references":["https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L330","https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L48","https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/ElementGenerator.php#L227","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L330","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L48","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/ElementGenerator.php#L227","https://plugins.trac.wordpress.org/changeset/3530843/kirki","https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799?source=cve"],"title":"Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'","updated":"2026-06-02T10:47:47.685000+00:00","vendors":[],"weaknesses":["CWE-269"]},"nvd":{"cpes":[],"created":"2026-06-02T04:17:03.550000+00:00","description":"The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-8206.json","references":["https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L330","https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L48","https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/ElementGenerator.php#L227","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L330","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L48","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/ElementGenerator.php#L227","https://plugins.trac.wordpress.org/changeset/3530843/kirki","https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799?source=cve"],"title":null,"updated":"2026-07-22T19:10:00.120000+00:00","vendors":[],"weaknesses":["CWE-269"]},"opencve":{"changes":[{"created":"2026-06-02T03:45:00+00:00","data":[{"details":{"new":"The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.","old":null},"type":"description"},{"details":{"new":"Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'","old":null},"type":"title"},{"details":{"added":["CWE-269"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L330","https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L48","https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/ElementGenerator.php#L227","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L330","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L48","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/ElementGenerator.php#L227","https://plugins.trac.wordpress.org/changeset/3530843/kirki","https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799?source=cve"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"ce2339fd-3181-4bb9-9e44-dd5c1cb80509"},{"created":"2026-06-02T05:00:00+00:00","data":[{"details":["themeum","themeum$PRODUCT$kirki_–_freeform_page_builder,_website_builder_&_customizer","wordpress","wordpress$PRODUCT$wordpress"],"type":"first_time"},{"details":{"added":["themeum","themeum$PRODUCT$kirki_–_freeform_page_builder,_website_builder_&_customizer","wordpress","wordpress$PRODUCT$wordpress"],"removed":[]},"type":"vendors"}],"id":"22663511-b5c0-4bf0-91c3-a5363a4b26bf"},{"created":"2026-06-02T11:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"941e97ce-55d2-4bab-b542-43df200fb422"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-06-02T03:28:49.326000+00:00","provider":"mitre"},"description":{"data":"The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00772},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L330","https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/CompLibFormHandler.php#L48","https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/ComponentLibrary/controller/ElementGenerator.php#L227","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L330","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/CompLibFormHandler.php#L48","https://plugins.trac.wordpress.org/browser/kirki/trunk/ComponentLibrary/controller/ElementGenerator.php#L227","https://plugins.trac.wordpress.org/changeset/3530843/kirki","https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799?source=cve"],"providers":["mitre","nvd"]},"title":{"data":"Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'","provider":"mitre"},"updated":{"data":"2026-06-02T10:47:47.685000+00:00","provider":"mitre"},"vendors":{"data":["themeum","themeum$PRODUCT$kirki_–_freeform_page_builder,_website_builder_&_customizer","wordpress","wordpress$PRODUCT$wordpress"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-269"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-06-02T03:28:49.326000+00:00","description":"The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'","updated":"2026-06-02T10:47:43.141000+00:00","vendors":[],"vulnrichment_repo_path":"2026/8xxx/CVE-2026-8206.json","weaknesses":[]}}