WordPress Plugin Vulnerabilities

Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'

Description

The plugin is vulnerable to privilege escalation via account takeover due to accepting an arbitrary email address when a username is supplied in the password reset request. This makes it possible for unauthenticated attackers to have the password reset link for any registered user — including administrators — sent to an attacker-controlled email address, leading to full account takeover.

Affects Plugins

Fixed in 6.0.7

References

Classification

Miscellaneous

Original Researcher
CHOIGYEONGMIN
Verified
No

Timeline

Publicly Published
2026-06-01 (about 1 month ago)
Added
2026-06-01 (about 1 month ago)
Last Updated
2026-07-27 (about 7 hours ago)

Other