logo

Critical WordPress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks

ID: 9d8c6c7c-f92e-5da6-9294-30b9d2bfcf61

STIX ID: report--9d8c6c7c-f92e-5da6-9294-30b9d2bfcf61

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Abinaya

...
...

A critical authentication-bypass vulnerability (CVE-2026-8181, CVSS 9.8) in the Burst Statistics WordPress plugin allows unauthenticated attackers to impersonate administrators via a flawed MainWP integration REST API handler; the flaw affects versions 3.4.0–3.4.1.1 and potentially exposes over 200,000 sites to full account takeover, though a patched release (3.4.2) and firewall protections were deployed shortly after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.