The active exploitation of the Burst Statistics WordPress plugin vulnerability shows how quickly attackers weaponize flaws in widely deployed plugins. CVE-2026-8181 allows unauthenticated attackers to impersonate known administrator users through REST API requests and, in the worst case, create rogue admin accounts without valid credentials. For a plugin installed on around 200,000 WordPress sites, this is not a minor website issue; it is a mass takeover risk.
Website owners should immediately upgrade Burst Statistics to version 3.4.2 or disable the plugin until patching is complete. They should also review administrator accounts, check for newly created users, inspect recent REST API activity, scan for backdoors, and rotate credentials if compromise is suspected. WordPress security cannot be reduced to “install plugin and forget,” which is apparently still the business model of chaos. A single vulnerable analytics plugin can become the front door to database theft, malware injection, redirects, and long-term persistence.
Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites. [...]
Source: Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin via Bleeping Computer — published 14 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.