---
schema: 1
kind: vulnerability
title: "CVE-2026-8206 + CVE-2026-8181 — Kirki and Burst Statistics WordPress plugins: unauthenticated account takeover under active mass-exploitation"
headline: "CVE-2026-8206 + CVE-2026-8181 — Kirki and Burst Statistics WordPress plugins: unauthenticated account takeover under active mass-exploitation"
summary: "Two WordPress plugins under active mass-exploitation give unauthenticated admin takeover. Kirki (CVE-2026-8206, 500k installs) and Burst Statistics (CVE-2026-8181, 200k installs) — REST-API auth-bypass / password-reset hijack, thousands of attacks blocked within 24 h of disclosure (SecurityWeek, 2026-06-03)."
discovered_at: "2026-06-04T05:00:06Z"
event_date: 2026-06-03
run_id: 2026-06-04-51b23ffa
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - auth-bypass
  - pre-auth
  - priv-esc
  - patch-available
regions:
  - global
sectors:
  - public-sector
  - technology
entities: []
cves:
  - id: CVE-2026-8206
    cvss: "9.8"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
  - id: CVE-2026-8181
    cvss: "9.8"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://www.securityweek.com/kirki-burst-statistics-wordpress-plugin-flaws-in-attackers-crosshairs/"
    publisher: SecurityWeek
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts/"
    publisher: BleepingComputer — Kirki
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin/"
    publisher: BleepingComputer — Burst Statistics
    role: corroborating
  - url: "https://www.heise.de/news/Angriffe-auf-Burst-Statistics-Plugin-fuer-WordPress-11317017.html"
    publisher: heise Security (DE)
    role: corroborating
  - url: "https://patchstack.com/database/wordpress/plugin/kirki/vulnerability/wordpress-kirki-plugin-6-0-0-6-0-6-unauthenticated-privilege-escalation-via-handle-forgot-password-vulnerability"
    publisher: Patchstack — Kirki advisory
    role: corroborating
closed_sources: []
evidence:
  - quote: Wordfence security blocked over 222 active exploitation attempts within 24 hours of public disclosure
    publisher: BleepingComputer
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-04.md
---

Two unauthenticated flaws in widely deployed WordPress plugins are under active mass-exploitation ([SecurityWeek, 2026-06-03](https://www.securityweek.com/kirki-burst-statistics-wordpress-plugin-flaws-in-attackers-crosshairs/)). **CVE-2026-8206 — Kirki Freeform Page Builder 6.0.0–6.0.6** (500k installs): the custom REST endpoint `handle_forgot_password()` accepts an attacker-supplied email alongside a victim username and routes the genuine reset link to the attacker, giving full takeover of any account including admin; Wordfence blocked 222+ attempts within 24 h of the 2 June disclosure, fix is v6.0.7 ([BleepingComputer, 2026-06-02](https://www.bleepingcomputer.com/news/security/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts/)). **CVE-2026-8181 — Burst Statistics, versions 3.4.0 through 3.4.1.1** (200k installs): the plugin mis-validates WordPress application passwords in its REST API authentication path, letting an unauthenticated attacker impersonate any known admin over the REST API and create rogue admin accounts (`T1136.001`); ~7,400 attacks blocked in a single 24 h peak, fix is v3.4.2 ([BleepingComputer, 2026-06-02](https://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin/) · [heise Security, 2026-06-03](https://www.heise.de/news/Angriffe-auf-Burst-Statistics-Plugin-fuer-WordPress-11317017.html)). Hunt WordPress access logs for unauthenticated REST calls to `/wp-json/kirki/*` and the Burst Statistics REST endpoints, and for unexpected admin-user creation.
