logo

Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin

ID: 85049a12-21f3-5f19-9b8d-911b7c634ff7

STIX ID: report--85049a12-21f3-5f19-9b8d-911b7c634ff7

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Bill Toulas

...
...

A critical authentication bypass (CVE-2026-8181) in the Burst Statistics WordPress plugin (introduced in v3.4.0 and present in v3.4.1) lets unauthenticated actors impersonate known administrator usernames or create new admin accounts via REST API requests by misinterpreting wp_authenticate_application_password() results; Wordfence has observed active exploitation (over 7,400 blocked attacks in 24 hours) and advises updating to the patched v3.4.2 or disabling the plugin—an estimated ~115,000 sites remain exposed, risking admin takeover, data access, backdoors, and malware distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.