Scworld
Critical Auth Bypass in Burst Statistics Plugin Enables Admin Takeover
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Hackers are exploiting a critical authentication bypass vulnerability in the Burst Statistics WordPress plugin, tracked as CVE-2026-8181. This flaw, introduced in version 3.4.0 and persisting in 3.4.1, affects approximately 200,000 WordPress sites. Discovered by Wordfence, the vulnerability allows unauthenticated attackers to impersonate existing administrators or create new admin accounts by exploiting REST API requests. Attackers can achieve this by supplying incorrect credentials in a Basic Authentication header, leading to unauthorized administrative actions. Over 7,400 attacks targeting this vulnerability have been blocked in the past 24 hours, indicating significant exploitation activity. Users are strongly advised to update to version 3.4.2 or disable the plugin to mitigate risks. The vulnerability poses severe risks, including data theft and malware distribution.
Key Points: • CVE-2026-8181 allows admin-level access via authentication bypass in Burst Statistics plugin. • The flaw affects around 200,000 WordPress sites, with over 7,400 attacks blocked in one day. • Users must update to version 3.4.2 or disable the plugin to prevent exploitation.