9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the request by supplying any random Basic Authentication password achieving privilege escalation.
AI Analysis
Authentication Bypass vulnerability in Burst Statistics WordPress plugin due to incorrect return-value handling in the `is_mainwp_authenticated()` function, allowing unauthenticated attackers to impersonate administrators.
Basic Information
ID
CVE-2026-8181
Source
Wordfence
Published
May 14, 2026 at 05:30
Affected Product
Vendor
burstbv
Product
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
Version
3.4.0
Affected Versions
burstbv Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) 3.4.0
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
burstbv
Product
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
Version
3.4.0, 3.4.1.1
References
- www.wordfence.com /threat-intel/vulnerabilities/id/8ca830d6-3d3c-4026-85cd-8447b8a568d3
- plugins.trac.wordpress.org /browser/burst-statistics/tags/3.4.1.1/includes/Frontend/class-mainwp-proxy.php
- plugins.trac.wordpress.org /browser/burst-statistics/trunk/includes/Frontend/class-mainwp-proxy.php
- plugins.trac.wordpress.org /browser/burst-statistics/trunk/includes/Frontend/class-mainwp-proxy.php
- plugins.trac.wordpress.org /browser/burst-statistics/tags/3.4.1.1/includes/Frontend/class-mainwp-proxy.php
- plugins.trac.wordpress.org /browser/burst-statistics/trunk/includes/Frontend/class-mainwp-proxy.php
- plugins.trac.wordpress.org /browser/burst-statistics/tags/3.4.1.1/includes/Frontend/class-mainwp-proxy.php
- plugins.trac.wordpress.org /browser/burst-statistics/trunk/includes/Traits/trait-admin-helper.php
- plugins.trac.wordpress.org /browser/burst-statistics/tags/3.4.1.1/includes/Traits/trait-admin-helper.php
- github.com /Burst-Statistics/burst-statistics/blob/2488d3fa54045e7e5342b0445b9f6b5eaac9ea7c/includes/Frontend/class-mainwp-proxy.php