IncidentAdmin Account Takeover via WordPress Plugin
What Happened On May 4, 2026, security researcher CHOIGYENGMIN reported CVE-2026-8206 to Wordfence: a critical vulnerability in the Kirki WordPress plugin that allows unauthenticated attackers to hija














