HomeSecurityWordPress: Hackers exploit Burst Statistics vulnerability

WordPress: Hackers exploit Burst Statistics vulnerability

A critical security vulnerability in the popular WordPress plugin Burst Statistics has raised alarm in the cybersecurity community, allowing attackers to gain administrative access to websites without proper authentication. The issue is already being actively exploited by hackers, with thousands of attacks recorded in just a few hours.

Burst Statistics WordPress

Burst Statistics is one of the most popular privacy-focused analytics plugins for WordPress, used by around 200,000 websites worldwide. The plugin is promoted as an alternative to Google Analytics, emphasizing privacy and consuming less server resources. However, the new vulnerability turns the tool into a potential gateway for full-scale website compromise.

The CVE-2026-8181 vulnerability and the serious security gap

The security issue, recorded as CVE-2026-8181 , was first discovered on May 8 by researchers at Wordfence, one of the most well-known WordPress security companies. The vulnerability was introduced on April 23 with the release of Burst Statistics version 3.4.0 and remained active in the subsequent version 3.4.1.

See also: CVE-2026-42897: Active Exchange Server vulnerability exploit

According to the technical analysis, the flaw allows unauthorized users to impersonate WordPress administrators during REST API requests. In a worst-case scenario, an attacker could create a new administrator account without requiring a previous login or regular authentication.

The vulnerability stems from incorrect handling of the “wp_authenticate_application_password()” function. The plugin code treated certain errors or “null” results as a successful authentication request, effectively allowing an attacker to declare an arbitrary administrator name and gain the corresponding access rights.

Simply put, the plugin incorrectly “believed” that the user was properly authenticated, even when the password was fake or invalid.

WordPress: Hackers exploit Burst Statistics vulnerability

How hackers gain access to websites

To exploit the flaw, attackers only need a valid administrator username. In many cases, these usernames are already publicly available through WordPress blog posts, author pages, comments, or public API endpoints.

But even if they are not immediately visible, hackers can use brute-force techniques or automated scans to guess common administrator usernames such as “admin”, “administrator” or editor names.

See also: New vulnerability in PraisonAI: Targeted a few hours after disclosure

Once administrator access is gained, the consequences can be devastating. Attackers can install backdoors, upload malware, redirect visitors to phishing pages, create new hidden administrator accounts , or even gain access to sensitive database data.

In many cases, such attacks are also exploited for SEO spam campaigns or for the creation of botnet networks used in future cyberattacks.

The attacks have already begun

While Wordfence initially warned that it “expects” the vulnerability to be targeted soon, the reality has proven even more worrisome. According to the company’s latest data, it has already blocked more than 7,400 attacks attempting to exploit CVE-2026-8181 in just 24 hours.

This number shows that exploit scripts have already been widely distributed online, allowing even less experienced attackers to target vulnerable WordPress installations en masse.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The speed with which the malicious activity began highlights a growing problem in the CMS platform space: cybercriminals now closely monitor vulnerability releases and automate their exploitation almost immediately.

WordPress: Hackers exploit Burst Statistics vulnerability

What WordPress administrators should do immediately

The creators of Burst Statistics have already released the patched version 3.4.2 on May 12, 2026, which resolves the critical security flaw. Experts recommend that website administrators upgrade immediately or, alternatively, disable the plugin completely until they confirm that their site is secure.

See also: NGINX Rift: Critical 18-year-old vulnerability allows RCE without authentication

Despite the patch, data from WordPress.org shows that around 115,000 websites may still be vulnerable. This means that a huge number of WordPress installations are still exposed.

The incident is yet another reminder that even popular plugins with an emphasis on privacy and security can become a serious risk when critical bugs appear in their code.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS