CVE-2026-8181
CVSS 9.8 CRITICAL: the Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. EPSS 15% (96th percentile).
Vulnerabilities · 123 days ago
A login check bug in Burst Statistics can turn a guessed admin username into full admin access, and in some cases let an attacker create a new administrator account. A password reset does not necessarily clear that access, because the flaw affects REST API requests and can leave a persistent foothold behind.
Wordfence says CVE-2026-8181 is being actively exploited in Burst Statistics 3.4.0 and 3.4.1, a plugin installed on about 200,000 WordPress sites. The issue is fixed in version 3.4.2.
For operators running the plugin, the risk is not just stolen credentials. The bigger problem is hidden admin persistence that can survive a routine incident response and keep the site under attacker control.
CVSS 9.8 CRITICAL: the Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. EPSS 15% (96th percentile).
1 source covering this story
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites.
Part of the PlainSec briefing for 2026-05-18