Tag: Burst Statistics WordPress plugin

Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
News

Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin

Hackers are gaining admin-level access to websites by taking advantage of a crucial authentication bypass vulnerability in the WordPress plugin Burst Statistics. A lightweight substitute for Google Analytics, Burst Statistics is a privacy-focused analytics plugin that is utilized on 200,000 WordPress websites. With the release of plugin version 3.4.0 on April 23, the vulnerability—tracked as CVE-2026-8181—was first discovered. The subsequent version, 3.4.1, likewise had the susceptible code. The vulnerability enables unauthenticated attackers to pose as known admin users during REST API calls and even create rogue admin accounts, according to Wordfence read more about Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin. Get up to date on the latest cyber...