Vulnerabilities & Exploits · Web App Attack

Burst Statistics Bug Turns WordPress Admins into Backdoors

A login check bug in Burst Statistics can turn a guessed admin username into full admin access, and in some cases let an attacker create a new administrator account. A password reset does not necessarily clear that access, because the flaw affects REST API requests and can leave a persistent foothold behind.

Wordfence says CVE-2026-8181 is being actively exploited in Burst Statistics 3.4.0 and 3.4.1, a plugin installed on about 200,000 WordPress sites. The issue is fixed in version 3.4.2.

For operators running the plugin, the risk is not just stolen credentials. The bigger problem is hidden admin persistence that can survive a routine incident response and keep the site under attacker control.

1 source · May 14

CVE-2026-8181

NVD KEV

CVSS 9.8 CRITICAL: the Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. EPSS 15% (96th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-18

Every edition of this story: Burst Statistics Bug Turns WordPress Admins into Backdoors

More from today