200K Sites at Risk: 9.8 CVSS RCE via Burst Statistics Auth Bypass Exploited in the Wild
ID: be82d641-ad2d-5d85-b7ed-4492b794c8c0
STIX ID: report--be82d641-ad2d-5d85-b7ed-4492b794c8c0
Feed Name: securityonline.info
Wordfence Threat Intelligence disclosed a critical authentication-bypass vulnerability (CVE-2026-8181, CVSS 9.8) in the Burst Statistics WordPress plugin (200k+ active installs). The flaw stems from incorrect handling of wp_authenticate_application_password() returning null, allowing attackers who know an administrator username to impersonate that user or create an admin account via the REST API; Wordfence reported blocking 5,318 attacks in 24 hours. Users are urged to update to Burst Statistics 3.4.2 or later immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
