Burst Statistics Bug Turns WordPress Admins into Backdoors

A login check bug in Burst Statistics can turn a guessed admin username into full admin access, and in some cases let an attacker create a new administrator account. A password reset does not necessarily clear that access, because the flaw affects REST API requests and can leave a persistent foothold behind. Wordfence says CVE-2026-8181 is being actively exploited in Burst Statistics 3.4.0 and 3.4.1, a plugin installed on about 200,000 WordPress sites. The issue is fixed in version 3.4.2. For operators running the plugin, the risk is not just stolen credentials. The bigger problem is hidden admin persistence that can survive a routine incident response and keep the site under attacker control.

Part of the PlainSec briefing for 2026-05-18

Sources