Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress
On May 8, 2026, a significant security vulnerability was identified in the Burst Statistics plugin, which boasts over 200,000 active installations. This Authentication Bypass flaw allows attackers, who know an administrator’s username, to impersonate that user and gain unauthorized access to the site’s REST API.
The affected versions are 3.4.0 to 3.4.1.1, and the vulnerability can enable attackers to create new administrator accounts without any authentication. This flaw was quickly patched in version 3.4.2, released just four days after its discovery, emphasizing the importance of timely updates.
To mitigate risks, users are urged to update to the latest version immediately. The risk level for this vulnerability is classified as critical, with a CVSS score of 9.8. Both Wordfence Premium users and those using the free version will receive protective measures against exploits, ensuring greater security for WordPress sites.
Source: View Original Report
