CVE-2026-8181
CVSS 9.8 CRITICAL: the Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. EPSS 3% (87º percentile).
Vulnerabilità · 138 giorni fa
Un bug nel controllo di login in Burst Statistics può trasformare un username admin indovinato in un accesso admin completo e, in alcuni casi, consentire a un aggressore di creare un nuovo account amministratore. Un reset della password non necessariamente elimina quell'accesso, perché la falla interessa richieste REST API e può lasciare dietro di sé un foothold persistente.
CVSS 9.8 CRITICAL: the Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. EPSS 3% (87º percentile).
1 fonte che coprono questa storia
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites.
Part of the PlainSec briefing for 2026-05-18