Critical WordPress Plugin Flaw Enables Authentication Bypass Attacks
ID: 81a7c35e-6461-51d6-8aa1-d99c5d896b6d
STIX ID: report--81a7c35e-6461-51d6-8aa1-d99c5d896b6d
Feed Name: Cyber Press
Threat Score
**Critical authentication bypass in Burst Statistics (CVE-2026-8181)** — A severe flaw in the MainWP integration of the Burst Statistics WordPress plugin (versions 3.4.0–3.4.1.1) allows unauthenticated attackers who know an admin username to gain full administrator access via a single REST API request; the issue (CVSS 9.8) was patched in version 3.4.2 on May 12, 2026, and Wordfence deployed firewall protections to mitigate exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
