Critical Auth Bypass in Burst Statistics Plugin Enables Admin Takeover

Critical Auth Bypass in Burst Statistics Plugin Enables Admin Takeover

First seen 15 May 2026, 18:25 UTC BleepingcomputerScworldCybersecuritynewswww.wordfence.com 91% similarity 72.0

Article Content

Browse articles
ThreatCluster

Hackers are exploiting a critical authentication bypass vulnerability in the Burst Statistics WordPress plugin, tracked as CVE-2026-8181. This flaw, introduced in version 3.4.0 and persisting in 3.4.1, affects approximately 200,000 WordPress sites. Discovered by Wordfence, the vulnerability allows unauthenticated attackers to impersonate existing administrators or create new admin accounts by exploiting REST API requests. Attackers can achieve this by supplying incorrect credentials in a Basic Authentication header, leading to unauthorized administrative actions. Over 7,400 attacks targeting this vulnerability have been blocked in the past 24 hours, indicating significant exploitation activity. Users are strongly advised to update to version 3.4.2 or disable the plugin to mitigate risks. The vulnerability poses severe risks, including data theft and malware distribution.

Key Points: • CVE-2026-8181 allows admin-level access via authentication bypass in Burst Statistics plugin. • The flaw affects around 200,000 WordPress sites, with over 7,400 attacks blocked in one day. • Users must update to version 3.4.2 or disable the plugin to prevent exploitation.

ThreatCluster AI

Timeline

2026-04-23
Version 3.4.0 released
The Burst Statistics plugin version 3.4.0 was released, introducing the critical vulnerability.
BleepingComputer
2026-05-08
Vulnerability discovered
Wordfence discovered the authentication bypass vulnerability, tracked as CVE-2026-8181.
BleepingComputer
2026-05-12
Patch released
Version 3.4.2 of the Burst Statistics plugin was released to address the vulnerability.
BleepingComputer
2026-05-14
CVE-2026-8181 published
CVE-2026-8181 was published, detailing the critical authentication bypass vulnerability.
BleepingComputer
2026-05-15
Active exploitation reported
Wordfence reported blocking over 7,400 attacks targeting the vulnerability within 24 hours.
Scworld

Community

Browse all →