Threat actors are exploiting recent Kirki and Burst Statistics WordPress plugin flaws leading to privilege escalation and site takeover.

Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to…

Angreifer missbrauchen eine kritische Lücke im WordPress-Plugin Burst Statistics. Sie ermöglicht die Übernahme von Instanzen.

Threat actors are exploiting recent Kirki and Burst Statistics WordPress plugin flaws leading to privilege escalation and site takeover.