Scworld Critical Auth Bypass in Burst Statistics Plugin Enables Admin Takeover
Article Content
- •CVE-2026-8181 allows admin-level access via authentication bypass in Burst Statistics plugin.
- •The flaw affects around 200,000 WordPress sites, with over 7,400 attacks blocked in one day.
- •Users must update to version 3.4.2 or disable the plugin to prevent exploitation.
Hackers are exploiting a critical authentication bypass vulnerability in the Burst Statistics WordPress plugin, tracked as CVE-2026-8181. This flaw, introduced in version 3.4.0 and persisting in 3.4.1, affects approximately 200,000 WordPress sites. Discovered by Wordfence, the vulnerability allows unauthenticated attackers to impersonate existing administrators or create new admin accounts by exploiting REST API requests. Attackers can achieve this by supplying incorrect credentials in a Basic Authentication header, leading to unauthorized administrative actions. Over 7,400 attacks targeting this vulnerability have been blocked in the past 24 hours, indicating significant exploitation activity. Users are strongly advised to update to version 3.4.2 or disable the plugin to mitigate risks. The vulnerability poses severe risks, including data theft and malware distribution.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-8181 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…