Critical WordPress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks
ID: 9d8c6c7c-f92e-5da6-9294-30b9d2bfcf61
STIX ID: report--9d8c6c7c-f92e-5da6-9294-30b9d2bfcf61
Feed Name: cybersecurityNews.com
Threat Score
A critical authentication-bypass vulnerability (CVE-2026-8181, CVSS 9.8) in the Burst Statistics WordPress plugin allows unauthenticated attackers to impersonate administrators via a flawed MainWP integration REST API handler; the flaw affects versions 3.4.0–3.4.1.1 and potentially exposes over 200,000 sites to full account takeover, though a patched release (3.4.2) and firewall protections were deployed shortly after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
