CVE-2026-8181
CVSS 9.8 CRITICAL: the Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. EPSS 15% (96th percentile).
Vulnerabilities & Exploits · Web App Attack
A login check bug in Burst Statistics can turn a guessed admin username into full admin access, and in some cases let an attacker create a new administrator account. A password reset does not necessarily clear that access, because the flaw affects REST API requests and can leave a persistent foothold behind.
Wordfence says CVE-2026-8181 is being actively exploited in Burst Statistics 3.4.0 and 3.4.1, a plugin installed on about 200,000 WordPress sites. The issue is fixed in version 3.4.2.
For operators running the plugin, the risk is not just stolen credentials. The bigger problem is hidden admin persistence that can survive a routine incident response and keep the site under attacker control.
1 source · May 14
CVSS 9.8 CRITICAL: the Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. EPSS 15% (96th percentile).
BleepingComputer
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites.
originalPart of the PlainSec briefing for 2026-05-17
Every edition of this story: Burst Statistics Bug Turns WordPress Admins into Backdoors