Il bug di Burst Statistics trasforma gli admin di WordPress in backdoor

Un bug nel controllo di login in Burst Statistics può trasformare un username admin indovinato in un accesso admin completo e, in alcuni casi, consentire a un aggressore di creare un nuovo account amministratore. Un reset della password non necessariamente elimina quell'accesso, perché la falla interessa richieste REST API e può lasciare dietro di sé un foothold persistente.

Part of the PlainSec briefing for 2026-05-18

Every edition of this story: Il bug di Burst Statistics trasforma gli admin di WordPress in backdoor

CVEs

Sources