WordPress Plugin Vulnerable To Active Attacks
The Kirki WordPress plugin is under active attack, with Wordfence detecting exploitation attempts. CVE-2026-8206 has been identified as the vulnerability affecting approximately 500,000 WordPress sites. This poses a risk to websites using the plugin.
Topics
Developing
- 884d Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore.
- 884d Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- 884d Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est.
- 884d Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium.
Sources · 7 independent
Bluesky Social
“CVE-2026-8206 Kirki Plugin Exploited; 500,000 WordPress Sites at Risk CVE-2026-8206 in the Kirki WordPress plugin is under active attack, with Wordfence detecting 222 exploitation attempts targetin”
GDELT Global Events
“WordPress Eklentisi Aktif Saldırılara Karşı Savunmasız”
Unlock the full story
Get a Pro subscription or above to see the live story progression and the full list of independent sources confirming each event as they happen.
Log in to upgrade