CVE-2026-8181Active Exploitation

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the request by supplying any random Basic Authentication password achieving privilege escalation.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 13 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 33 mentions across 18 observed days

What's happening

  • Active exploitation reported across 13 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 25 signals
  • Disclosure: 10 classified signals
  • Peaked 17d ago at 8 mentions (2026-05-14); latest day: 1
  • 33 total mentions across 18 days

Deep dive

Activity timeline33 mentions / 18d
02468Mentions · 2026-05-14: 8Mentions · 2026-05-15: 5Mentions · 2026-05-16: 1Mentions · 2026-05-17: 1Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1Mentions · 2026-05-20: 2Mentions · 2026-05-21: 1Mentions · 2026-05-22: 2Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1Mentions · 2026-06-01: 1Mentions · 2026-06-02: 3Mentions · 2026-06-03: 1Mentions · 2026-06-08: 1Mentions · 2026-06-09: 1Mentions · 2026-06-10: 1Mentions · 2026-06-15: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-22: 2PoC Mentioned / Linked · 2026-06-15: 1Exploit Tool / Code · 2026-05-15: 2Exploit Tool / Code · 2026-05-22: 1Exploit Tool / Code · 2026-06-15: 1Active Exploitation · 2026-05-14: 3Active Exploitation · 2026-05-15: 3Active Exploitation · 2026-05-16: 1Active Exploitation · 2026-05-17: 1Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-06-02: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-06-10: 1Patch / Workaround · 2026-05-14: 5Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-06-02: 1Patch / Workaround · 2026-06-09: 1Technical Details · 2026-05-14: 8Technical Details · 2026-05-15: 3Technical Details · 2026-05-16: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 2Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-02: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-09: 105-1405-1505-1605-1705-1805-1905-2005-2105-2205-2405-2506-0106-0206-0306-0806-0906-1006-15
Signal classification5 categories
Active Exploitation
1133.3%
Disclosure
1030.3%
Patch
618.2%
PoC
412.1%
General
26.1%
Referenced assets24 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-148
Active Exploitation2Disclosure4Patch2
2026-05-155
Active Exploitation3General1PoC1
2026-05-161
Active Exploitation1
2026-05-171
Active Exploitation1
2026-05-181
Patch1
2026-05-191
Disclosure1
2026-05-202
Disclosure1Patch1
2026-05-211
Disclosure1
2026-05-222
PoC2
2026-05-241
General1
2026-05-251
Disclosure1
2026-06-011
Patch1
2026-06-023
Active Exploitation1Disclosure1Patch1
2026-06-031
Disclosure1
2026-06-081
Active Exploitation1
2026-06-091
Active Exploitation1
2026-06-101
Active Exploitation1
2026-06-151
PoC1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    200,000+ sites hit by CVE-2026-8181. A 9.8 CVSS Burst Statistics flaw allows RCE via auth bypass. 5,000+ attacks blocked. Update to 3.4.2 immediately! #WordPress #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #CVE #BurstStatistics #ExploitAlert https://securityonline.info/burst-statistics-authentication-bypass-cve-2026-8181-exploited/ https://t.co/UoRnDY6PvT

    Post summary

    The tweet alerts on a widespread RCE vulnerability (CVE‑2026‑8181) affecting over 200,000 WordPress sites, confirms active exploitation, and urges an immediate update to version 3.4.2.

    113184216.7K
    12.5K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Aprovechan vulnerabilidad de bypass de autenticación en el plugin Burst Statistics de WordPress Están explotando una vulnerabilidad crítica (CVE-2026-8181) en el plugin de WordPress Burst Statistics https://blog.elhacker.net/2026/05/aprovechan-vulnerabilidad-de-bypass-de.html

    Post summary

    The post reports that CVE‑2026‑8181, an authentication bypass issue in the WordPress Burst Statistics plugin, is currently being exploited in the wild.

    0301151.8K
    141.0K followersView on X
  • Danny van Kooten@dannyvankooten
    PoC

    Reading through the exploit script is quite informative. https://github.com/whattheslime/CVE-2026-8181 Like, hiding NGINX version is a very common precaution mechanism. Should it be this easy (GET /readme.txt) or using the cache bust parameter from wp_enqueue_script etc. to get the version for any active plugin?

    Post summary

    The post points to a publicly shared exploit script for CVE-2026-8181, demonstrating a proof‑of‑concept, but does not discuss active exploitation, patches, or false positive status.

    10051646
    579 followersView on X
  • サイトドック|Webサイト無料健診@sitedock_jp
    Active Exploitation

    WordPressプラグイン認証バイパス脆弱性(CVE-2026-8181)の攻撃が続発。11.5万以上のサイトが未更新の可能性とみられています。v3.4.2以降に即時更新を推奨。診断: https://sitedock.jp/ #セキュリティ #WordPress https://t.co/dPs9fjgy87

    Post summary

    The tweet highlights ongoing exploitation of CVE-2026-8181 (authentication bypass) affecting over 115,000 WordPress sites, urges immediate patching to v3.4.2, but does not provide exploit code or in‑depth technical details.

    0003055
    11 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    WordPress Burst Statistics の脆弱性 CVE-2026-8181 が FIX:管理者権限奪取の可能性 https://iototsecnews.jp/2026/05/14/critical-wordpress-plugin-flaw-allows-unauthorized-access-to-websites/ WordPress のプラグイン Burst Statistics で見つかった、認証バイパスの脆弱性について解説する記事です。問題の原因は、他のシステムとの統合機能において、認証結果の検証処理に不備があったことにあります。具体的には、認証関数がエラーではない応答 (null など) を受け取った際、それを正しい認証成功と誤認してしまう設計になっていました。この CVE-2026-8181 を悪用する攻撃者は、管理者のユーザー名さえ分かれば、REST API 経由で管理者になりすますことが可能です。最悪の場合、新しい管理者アカウントが作成され、Web サイトの完全な権限が奪われる可能性があるため、注意が必要です。 #BurstStatistics #CVE20268181 #Vulnerability #WordPress

    Post summary

    The article announces a critical authentication bypass flaw (CVE‑2026‑8181) in the WordPress Burst Statistics plugin, detailing how attackers can be granted full admin access via the REST API if they know a username. No patch, exploit code, or active exploitation evidence is provided.

    11010219
    489 followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Critical auth bypass in Burst Statistics WordPress plugin (CVE-2026-8181, CVSS 9.8) allows unauthenticated attackers to impersonate admin users via malformed Basic Auth headers. Update to version 3.4.2 immediately — 200k+ sites affected. #DFIR_Radar https://t.co/K0lAnmMLI5

    Post summary

    The tweet alerts to a critical authentication bypass in Burst Statistics WordPress plugin (CVE-2026-8181) and urges affected users to update immediately to version 3.4.2 to mitigate the risk.

    10020193
    1.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-8181 (CVSS 9.8) in WordPress Burst Statistics plugin allows auth bypass with just admin username knowledge. 112,800+ exploit attempts blocked since May 13th disclosure. #DFIR_Radar https://t.co/hya3s3w7Sv

    Post summary

    CVE-2026-8181 is a severe authentication bypass in the WordPress Burst Statistics plugin, with evidence of more than 112,000 exploitation attempts since its disclosure.

    11000174
    1.6K followersView on X
  • Cloud Virtues@CloudVirtues
    PoC

    CVE-2026-8181 - Burst Statistics Auth Bypass vulnerability https://dy.si/7JsCSU https://t.co/3mtZ0xM3jR

    Post summary

    The post references CVE-2026-8181, describing it as an authentication bypass in Burst Statistics and linking to external resources that likely contain a proof‑of‑concept or further details.

    000206
    12 followersView on X
  • Tre B@trerbbb
    Active Exploitation

    wordpress CVE-2026-8181: auth bypass. shared hosting + outdated CMS = a botnet recruitment ad. assume compromise if you cant patch fast. #AuthBypass #WordPress #CVE-2026-8181 https://valtikstudios.com

    Post summary

    The post highlights that CVE-2026-8181 is an authentication bypass being actively exploited for botnet recruitment, urging users to patch quickly; no PoC or detailed exploit is disclosed.

    0101078
    15 followersView on X
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 In this week’s newsletter, we cover CVE-2026-8181, a critical authentication bypass vulnerability in the WordPress Burst Statistics plugin now under active exploitation. We break down how attackers can obtain administrative privileges without valid credentials and what defenders should do next. Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2026-8181-wordpress-burst-statistics-authentication-bypass

    Post summary

    The text reports that CVE‑2026‑8181 is a critical authentication bypass vulnerability in the WordPress Burst Statistics plugin, currently being exploited in the wild to gain administrative privileges.

    00010253
    19.5K followersView on X
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Disclosure

    おはモー🐮 【木曜朝のCVE警戒5発】6月初週、大型脆弱性が連発モー🐮 🔴 Kirki CVE-2026-8206(CVSS 9.8、15万サイト) 🔴 Burst Statistics CVE-2026-8181(20万インストール) 🔴 Redis RCE CVE-2026-23479(2年潜伏のUse-After-Free) 🔴 IBM WebSphere CVE-2026-9319 🔴 M365 Android FlagLeft(トークン窃取) WP保守+バックエンド連携の人は週次棚卸しタイミングだモー🐮 #おは戦80604jm🌴 #WordPressセキュリティ

    Post summary

    The post announces five newly discovered high‑impact CVEs, providing brief technical details but no exploit, PoC, or mitigation information.

    0001074
    767 followersView on X
  • Dr. Siraj Dokadia@SirajD_Official
    Disclosure

    CVE-2026-8181 - Burst Statistics Auth Bypass vulnerability https://bit.ly/4u8WfcE https://t.co/Phg7nUhX59

    Post summary

    The tweet announces CVE-2026-8181, an authentication bypass in Burst Statistics, and links to additional content via short URLs, but offers no detailed technical or exploit information.

    0001048
    17 followersView on X
  • Threat Intelligence@threatintel
    Disclosure

    #ThreatProtection #CVE-2026-8181 - Burst Statistics Auth Bypass #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2026-8181-burst-statistics-auth-bypass-vulnerability

    Post summary

    The tweet cites CVE‑2026‑8181 and points to a Broadcom bulletin titled ‘Burst Statistics Auth Bypass’, but provides no PoC, exploitation details, or patch information.

    010001.5K
    115.1K followersView on X
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Patch

    【WP緊急】Burst Statistics プラグインに認証バイパス脆弱性(CVE-2026-8181, CVSS 9.8)モー🐮 影響: v3.4.0〜3.4.1.1、約20万サイト 📌 確認: 管理画面→プラグイン→バージョン 🔧 対応: 即時アップデート 🔍 ログ: REST API/ログイン履歴/X-BurstMainWP ヘッダー 朝イチ1分でいいから確認モー🐮 #WordPressセキュリティ

    Post summary

    Alert reports an authentication bypass vulnerability (CVE‑2026‑8181) in Burst Statistics plugin (v3.4.0‑3.4.1.1) with CVSS 9.8, affecting roughly 200,000 sites; immediate update is advised.

    10000160
    756 followersView on X
  • Mj | Cybersecurity@mj_nw01
    General

    الثغرة تحمل المعرف: CVE-2026-8181 وتأثر على الإصدارات: 3.4.0 و 3.4.1

    Post summary

    The text announces CVE-2026-8181 and states it affects versions 3.4.0 and 3.4.1, without providing further details.

    00001344
    3.5K followersView on X
  • mürrez@murrezsec
    PoC

    CVE-2026-8181 PoC: Burst Statistics (3.4.0–3.4.1.1) authentication bypass. Python tool — single & multi-target scans, threaded workers, TXT reports. Authorized testing only. https://github.com/murrez/CVE-2026-8181 https://t.co/dFzHwapChQ

    Post summary

    A PoC for CVE-2026-8181 is presented, revealing an authentication bypass in Burst Statistics 3.4.0–3.4.1.1, accompanied by a GitHub-hosted Python tool for testing.

    00010176
    591 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-8181 — CVSS 9.8/10 ██████████ The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/39HOa0oYI5

    Post summary

    The tweet alerts about the critical CVE-2026-8181 affecting a WordPress analytics plugin, provides severity details, and urges users to apply the patch immediately.

    1000081
    34 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-8181 The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vuln… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-8181 #Google #CyberSecurity #InfoSec

    Post summary

    CVE-2026-8181, a critical flaw in the Burst Statistics WordPress plugin, has been disclosed with a high CVSS score (9.8) and no patch available; no PoC, exploit, or evidence of active exploitation has been reported.

    0001058
    90 followersView on X
  • ASTRAL@MeAstraL
    Disclosure

    200,000 #WordPress Sites at Risk from Critical #Authentication Bypass #Vulnerability in Burst Statistics Plugin #⃣CVSS Rating : 9.8 (Critical) 🆔CVE-ID : CVE-2026-8181 🎯Affected Version(s) : 3.4.0 - 3.4.1.1 ✅Patched Version : 3.4.2 #UpdateNow #WP

    Post summary

    A critical authentication bypass vulnerability (CVE‑2026‑8181) was disclosed for WordPress Burst Statistics plugin versions 3.4.0‑3.4.1.1, with a CVSS score of 9.8 and an available patched version 3.4.2.

    00100105
    367 followersView on X
  • Dr.Philippe Vynckier, CISSP - Influencer@PVynckier
    Active Exploitation

    CVE-2026-8181 : le plugin WordPress Burst Statistics visé par une exploitation active - IT SOCIAL https://itsocial.fr/cybersecurite/cybersecurite-actualites/cve-2026-8181-le-plugin-wordpress-burst-statistics-vise-par-une-exploitation-active/

    Post summary

    CVE‑2026‑8181 affects the WordPress Burst Statistics plugin and is reported to be actively exploited, but no PoC, exploit code, patch, or detailed technical information is included.

    0000079
    24.0K followersView on X

Explore more