logo

Critical WordPress Plugin Flaw Allows Unauthorized Access to Websites

ID: b28d4e28-4c88-50fb-b984-e8d9512bbc45

STIX ID: report--b28d4e28-4c88-50fb-b984-e8d9512bbc45

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Divya

...
...

A critical authentication bypass (CVE-2026-8181, CVSS 9.8) was discovered in the Burst Statistics WordPress plugin (versions 3.4.0–3.4.1.1), allowing attackers who know a valid administrator username to craft REST API requests that impersonate administrators and potentially create persistent admin accounts; the issue affects roughly 200,000 sites, was quickly patched in version 3.4.2, and Wordfence has deployed firewall rules to protect users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.