Skip to content
Critical Auth Bypass in Burst Statistics Plugin Enables Admin Takeover

Critical Auth Bypass in Burst Statistics Plugin Enables Admin Takeover

First seen 15 May 2026, 18:25 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 16, 2026 at 17:49 UTC
  • CVE-2026-8181 allows admin-level access via authentication bypass in Burst Statistics plugin.
  • The flaw affects around 200,000 WordPress sites, with over 7,400 attacks blocked in one day.
  • Users must update to version 3.4.2 or disable the plugin to prevent exploitation.

Hackers are exploiting a critical authentication bypass vulnerability in the Burst Statistics WordPress plugin, tracked as CVE-2026-8181. This flaw, introduced in version 3.4.0 and persisting in 3.4.1, affects approximately 200,000 WordPress sites. Discovered by Wordfence, the vulnerability allows unauthenticated attackers to impersonate existing administrators or create new admin accounts by exploiting REST API requests. Attackers can achieve this by supplying incorrect credentials in a Basic Authentication header, leading to unauthorized administrative actions. Over 7,400 attacks targeting this vulnerability have been blocked in the past 24 hours, indicating significant exploitation activity. Users are strongly advised to update to version 3.4.2 or disable the plugin to mitigate risks. The vulnerability poses severe risks, including data theft and malware distribution.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 127d ago How this analysis works

Timeline

2026-04-23
Version 3.4.0 released
The Burst Statistics plugin version 3.4.0 was released, introducing the critical vulnerability.
BleepingComputer
2026-05-08
Vulnerability discovered
Wordfence discovered the authentication bypass vulnerability, tracked as CVE-2026-8181.
BleepingComputer
2026-05-12
Patch released
Version 3.4.2 of the Burst Statistics plugin was released to address the vulnerability.
BleepingComputer
2026-05-14
CVE-2026-8181 published
CVE-2026-8181 was published, detailing the critical authentication bypass vulnerability.
BleepingComputer
2026-05-15
Active exploitation reported
Wordfence reported blocking over 7,400 attacks targeting the vulnerability within 24 hours.
Scworld

More articles in this cluster (5)

Following this threat?

Track CVE-2026-8181 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed