Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A critical vulnerability in the Kirki WordPress plugin (versions 6.0.0-6.0.6) allows any unauthenticated attacker to take over any user account, including administrator accounts, by redirecting password reset emails to an attacker-controlled address. No credentials, prior access, or user interaction are required, and the attack is trivially repeatable at scale. Organizations running WordPress sites with this plugin face immediate risk of complete site compromise, data theft, and defacement.

Author

Tech Jacks Solutions