Critical Kirki flaw exploited to hijack WordPress admin accounts
… This behavior makes it trivial for unauthenticated attackers to generate password reset links for any user registered on the site to email addresses under their control, easily hijacking them. …