CVE-2026-8181
CVSS 9.8 CRITICAL: the Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. EPSS 3% (87º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Un bug nel controllo di login in Burst Statistics può trasformare un username admin indovinato in un accesso admin completo e, in alcuni casi, consentire a un aggressore di creare un nuovo account amministratore. Un reset della password non necessariamente elimina quell'accesso, perché la falla interessa richieste REST API e può lasciare dietro di sé un foothold persistente.
1 fonte · 14 mag
CVSS 9.8 CRITICAL: the Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. EPSS 3% (87º percentile).
BleepingComputer
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites.
originalePart of the PlainSec briefing for 2026-05-15
Every edition of this story: Il bug di Burst Statistics trasforma gli admin di WordPress in backdoor