Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
ID: 85049a12-21f3-5f19-9b8d-911b7c634ff7
STIX ID: report--85049a12-21f3-5f19-9b8d-911b7c634ff7
Feed Name: Bleeping Computer
A critical authentication bypass (CVE-2026-8181) in the Burst Statistics WordPress plugin (introduced in v3.4.0 and present in v3.4.1) lets unauthenticated actors impersonate known administrator usernames or create new admin accounts via REST API requests by misinterpreting wp_authenticate_application_password() results; Wordfence has observed active exploitation (over 7,400 blocked attacks in 24 hours) and advises updating to the patched v3.4.2 or disabling the plugin—an estimated ~115,000 sites remain exposed, risking admin takeover, data access, backdoors, and malware distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
