Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Plugin Vulnerabilities Threaten Websites

WordPress Plugin Vulnerabilities Threaten Websites

Posted on June 3, 2026 By CWS

Hundreds of thousands of websites are currently at risk due to vulnerabilities identified in two popular WordPress plugins, Kirki and Burst Statistics. Security experts at Defiant have raised alarms about these flaws, which could allow attackers to exploit sites using these plugins.

Kirki Plugin Security Flaw

Kirki, known for enhancing WordPress customization and page creation, has been flagged for a critical vulnerability affecting its versions 6.0.0 to 6.0.6. This flaw, tracked as CVE-2026-8206 with a severity score of 9.8, compromises the password reset mechanism. Attackers can manipulate this feature by providing a username and a fabricated email address, receiving a password reset key at the attacker-controlled email.

This security lapse permits attackers to reset the password of a high-privilege account, potentially taking over the entire WordPress site. It highlights a significant risk to site administrators who have not yet updated to the latest plugin version.

Burst Statistics Vulnerability

Burst Statistics, a tool offering analytics insights for WordPress users, is also under scrutiny. Versions 3.4.0 to 3.4.1.1 suffer from an authentication bypass vulnerability. This issue allows unauthorized users to elevate their privileges and assume administrator rights on a compromised site.

The vulnerability arises from a flaw in the validation of application passwords, enabling attackers to exploit the REST API and temporarily impersonate an administrator. The implications include unauthorized access to critical administrative functions, such as creating new admin accounts.

Preventive Measures and Recommendations

Defiant reports blocking thousands of attack attempts targeting these vulnerabilities in just 24 hours. They caution that a significant number of sites remain vulnerable, with Kirki installed on over 500,000 sites and Burst Statistics on more than 200,000.

To safeguard against these threats, users are strongly advised to update their plugins. The latest secure versions are Kirki 6.0.7 and Burst Statistics 3.4.2. These updates contain patches that address the security concerns identified.

In conclusion, staying vigilant and ensuring plugins are updated promptly is crucial in maintaining website security. As cyber threats evolve, proactive measures are essential to protect digital assets from exploitation.

Security Week News Tags:authentication bypass, Burst Statistics, CVE-2026-8206, Cybersecurity, Defiant, Kirki, plugin vulnerabilities, privilege escalation, website security, WordPress

Post navigation

Previous Post: GitHub OAuth Tokens Vulnerable to One-Click Attack
Next Post: Ivanti ITSM Vulnerability Risks Admin Access

Related Posts

Microsoft Dissects PipeMagic Modular Backdoor Microsoft Dissects PipeMagic Modular Backdoor Security Week News
Kimwolf Android Botnet Grows Through Residential Proxy Networks Kimwolf Android Botnet Grows Through Residential Proxy Networks Security Week News
Hush Security Emerges Stealth to Eliminate Credential Threats With No-Secrets Platform Hush Security Emerges Stealth to Eliminate Credential Threats With No-Secrets Platform Security Week News
High-Severity Flaws Patched in Chrome, Firefox High-Severity Flaws Patched in Chrome, Firefox Security Week News
Valarian Bags M Seed Capital for ‘Isolation-First’ Infrastructure Tech Valarian Bags $20M Seed Capital for ‘Isolation-First’ Infrastructure Tech Security Week News
40,000 Servers at Risk Due to cPanel Exploit 40,000 Servers at Risk Due to cPanel Exploit Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Claude Code to Steal OAuth Tokens
  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Claude Code to Steal OAuth Tokens
  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark