Reliable Penguin has reviewed managed WordPress servers for a recently disclosed vulnerability in the Kirki WordPress plugin.
Wordfence published an advisory for a critical unauthenticated privilege escalation vulnerability in the Kirki WordPress plugin. The issue affects Kirki versions 6.0.0 through 6.0.6 and is patched in version 6.0.7. Wordfence assigned the vulnerability a CVSS score of 9.8, which is considered critical. The vulnerability can allow an unauthenticated attacker to take over user accounts, including administrator accounts, by abusing the plugin’s password reset functionality.
Reliable Penguin used our internal RP Anvil system to review managed servers for WordPress installations using vulnerable Kirki plugin versions.
As part of this review, RP Anvil scanned managed systems for Kirki plugin installations and checked installed versions against the vulnerable range identified in the advisory.
At this time:
Managed servers have been reviewed.
Clients with vulnerable WordPress installations have been notified directly.
No client action is required at this point for Reliable Penguin managed systems unless we have contacted you directly.
For Reliable Penguin managed systems, no action is required unless you have received a direct notification from us.
For WordPress sites not managed by Reliable Penguin, site owners should review their installations and update Kirki to version 6.0.7 or newer. Wordfence recommends updating as soon as possible due to the critical nature of this vulnerability.
Wordfence: Unauthenticated Privilege Escalation Vulnerability Patched in Kirki WordPress Plugin
https://www.wordfence.com/blog/2026/06/unauthenticated-privilege-escalation-vulnerability-patched-in-kirki-wordpress-plugin/
Wordfence Intelligence vulnerability summary for Kirki
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki/
Kirki plugin page on WordPress.org
https://wordpress.org/plugins/kirki/
If you have questions about this vulnerability or your managed WordPress environment, please contact Reliable Penguin support.