CVE 9.8 CRITICAL

Burst Statistics 3.4.0 – 3.4.1.1 – Authentication Bypass to Admin Account Takeover_CVE-2026-8181

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the request by supplying any random Basic Authentication password achieving privilege escalation.

AI Analysis

Authentication Bypass vulnerability in Burst Statistics WordPress plugin due to incorrect return-value handling in the `is_mainwp_authenticated()` function, allowing unauthenticated attackers to impersonate administrators.

Basic Information

ID CVE-2026-8181
Source Wordfence
Published May 14, 2026 at 05:30

Affected Product

Vendor burstbv
Product Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
Version 3.4.0
Affected Versions burstbv Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) 3.4.0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor burstbv
Product Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
Version 3.4.0, 3.4.1.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.