logo

Critical WordPress Plugin Flaw Enables Authentication Bypass Attacks

ID: 81a7c35e-6461-51d6-8aa1-d99c5d896b6d

STIX ID: report--81a7c35e-6461-51d6-8aa1-d99c5d896b6d

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: AnuPriya

...
...

**Critical authentication bypass in Burst Statistics (CVE-2026-8181)** — A severe flaw in the MainWP integration of the Burst Statistics WordPress plugin (versions 3.4.0–3.4.1.1) allows unauthenticated attackers who know an admin username to gain full administrator access via a single REST API request; the issue (CVSS 9.8) was patched in version 3.4.2 on May 12, 2026, and Wordfence deployed firewall protections to mitigate exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.