A critical Burst Statistics flaw is now under active exploitation, putting thousands of WordPress websites at risk of administrator account takeover. The vulnerability affects Burst Statistics, a privacy-focused analytics plugin used on more than 200,000 WordPress sites. Attackers can exploit the bug to impersonate known administrator users during REST API requests. The issue is tracked…