A critical Burst Statistics flaw is now under active exploitation, putting thousands of WordPress websites at risk of administrator account takeover.
The vulnerability affects Burst Statistics, a privacy-focused analytics plugin used on more than 200,000 WordPress sites. Attackers can exploit the bug to impersonate known administrator users during REST API requests.
The issue is tracked as CVE-2026-8181. Researchers said it entered the plugin on April 23, 2026, with version 3.4.0. The vulnerable code also appeared in version 3.4.1.
Attackers Can Impersonate Admin Users
The Burst Statistics flaw stems from incorrect handling of WordPress application password authentication.
Researchers said attackers only need to know a valid administrator username. They can then send a specially crafted request with any password in the authentication header.
The vulnerable plugin may treat the failed authentication attempt as valid. As a result, the attacker can act as that administrator during the REST API request.
In the worst case, attackers could create a new administrator account without valid login credentials.
Compromised Sites Face Serious Risks
Administrator-level access gives attackers broad control over a WordPress site. They could access private databases, install backdoors, redirect visitors, publish malicious content, or distribute malware.
The risk is especially serious because administrator usernames can often be exposed through blog posts, comments, public API responses, or guessing attempts.
Researchers warned that attacks have already started. Wordfence reportedly blocked more than 7,400 exploitation attempts within 24 hours.
Site Owners Should Update Immediately
Website owners using Burst Statistics should update to version 3.4.2 immediately. The patched release became available on May 12, 2026.
Administrators who cannot update right away should disable the plugin until they can safely install the fixed version.
Site owners should also review administrator accounts, remove unknown users, inspect recent plugin changes, and check for suspicious redirects or backdoors.
WordPress Plugin Security Remains a Major Target
The Burst Statistics flaw highlights why WordPress plugin security remains a constant challenge for site owners.
Attackers often move quickly after critical plugin vulnerabilities become public. Authentication bypass bugs are especially dangerous because they can skip normal login protections and give attackers direct control.
This incident also shows why website owners need strict plugin update routines, account monitoring, and regular security reviews.
Conclusion
The actively exploited Burst Statistics flaw creates serious risks for WordPress sites running vulnerable plugin versions.
Because attackers can potentially gain administrator-level access without valid credentials, affected site owners should update immediately, review privileged accounts, and check for signs of compromise.


0 responses to “Burst Statistics flaw exploited in WordPress admin attacks”