Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisoryidentity-authentication-vulnerability

Burst Statistics WordPress Plugin Flaw Enables Admin Takeover Under Active Exploitation

Updated 1mo agoFirst seen May 14, 20263 sources

A critical authentication-bypass flaw in the Burst Statistics WordPress plugin is being actively exploited to seize administrator access on vulnerable sites. Tracked as CVE-2026-8181, the bug affects versions 3.4.0 through 3.4.1.1 and was introduced through improper return-value handling in the plugin’s is_mainwp_authenticated() logic for Basic Authentication headers. Security researchers reported that an unauthenticated attacker who knows an administrator username can send arbitrary credentials and be treated as that admin for the request, allowing account impersonation or creation of new administrator accounts on sites running the plugin, which is installed on roughly 200,000 WordPress websites.

Wordfence said it observed live attacks and blocked more than 7,400 exploitation attempts in a 24-hour period. Successful compromise could enable follow-on activity including data theft, malware deployment, and malicious site redirection. Defenders were urged to update immediately to Burst Statistics 3.4.2 or disable the plugin until patching is possible. Separate disclosures also highlighted another severe WordPress plugin issue, CVE-2026-6510 in InfusedWoo Pro <= 5.1.2, where missing authorization checks in the iwar_save_recipe() AJAX handler can let unauthenticated attackers craft automation-based authentication bypass leading to administrator-level privilege escalation.

Share:
Burst Statistics WordPress Plugin Flaw Enables Admin Takeover Under Active Exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 15, 20261mo ago

Burst Statistics users advised to update to version 3.4.2

Defenders were advised to patch Burst Statistics to version 3.4.2 or disable the plugin if immediate patching was not possible. The update addressed the critical authentication bypass affecting roughly 200,000 WordPress sites.

Active exploitation of Burst Statistics vulnerability observed

Wordfence reported active exploitation of CVE-2026-8181 against Burst Statistics sites and said it blocked more than 7,400 attack attempts within a 24-hour period. Successful attacks could enable admin account creation, data theft, malware delivery, or site redirection.

May 14, 20261mo ago

CVE-2026-6510 assigned for InfusedWoo Pro privilege-escalation flaw

A new CVE, CVE-2026-6510, was assigned on 2026-05-14 for a critical InfusedWoo Pro vulnerability affecting versions through 5.1.2. The issue allows unauthenticated attackers to create a malicious automation recipe that can lead to administrator-level account takeover.

Wordfence receives and documents CVE-2026-8181 report

Wordfence received the Burst Statistics authentication bypass vulnerability report on 2026-05-14 and documented that incorrect handling of Basic Authentication could let unauthenticated attackers impersonate an administrator during a request.

Burst Statistics flaw introduced in plugin version 3.4.0

The authentication bypass vulnerability later tracked as CVE-2026-8181 was introduced in Burst Statistics version 3.4.0. The flaw affected subsequent releases including 3.4.1 and 3.4.1.1.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.