logo

200K Sites at Risk: 9.8 CVSS RCE via Burst Statistics Auth Bypass Exploited in the Wild

ID: be82d641-ad2d-5d85-b7ed-4492b794c8c0

STIX ID: report--be82d641-ad2d-5d85-b7ed-4492b794c8c0

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-22

Author: Ddos

...
...

Wordfence Threat Intelligence disclosed a critical authentication-bypass vulnerability (CVE-2026-8181, CVSS 9.8) in the Burst Statistics WordPress plugin (200k+ active installs). The flaw stems from incorrect handling of wp_authenticate_application_password() returning null, allowing attackers who know an administrator username to impersonate that user or create an admin account via the REST API; Wordfence reported blocking 5,318 attacks in 24 hours. Users are urged to update to Burst Statistics 3.4.2 or later immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.