
Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.
| **Authentication Required
CVE-2026-8181 is a critical Authentication Bypass vulnerability in the Burst Statistics WordPress plugin (versions 3.4.0 - 3.4.1.1). This flaw allows an unauthenticated attacker to impersonate any administrator by exploiting incorrect return-value handling in the is_mainwp_authenticated() function when validating application passwords from the Authorization header.
| Fact | Details |
|---|---|
| CVE ID | CVE-2026-8181 |
| CVSS Score | 9.8 (Critical) |
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Plugin | Burst Statistics (Google Analytics Alternative) |
| Affected Versions | 3.4.0 β 3.4.1.1 |
| Patched Version | 3.4.2 |
| Attack Type | Authentication Bypass / Privilege Escalation |
| ** | β None |
| User Interaction | β None |
The vulnerability exists in the is_mainwp_authenticated() function of the Burst Statistics plugin. The flaw is triggered by:
CVE-2026-8181 is a critical Authentication Bypass vulnerability in the Burst Statistics WordPress plugin (versions 3.4.0 - 3.4.1.1). This flaw allows an unauthenticated attacker to impersonate any administrator by exploiting incorrect return-value handling in the is_mainwp_authenticated() function when validating application passwords from the Authorization header.