Burst Statistics authentication bypass (CVE-2026-8181)
Vulnerability
Summary
Hide ▲
Show ▼
Burst Statistics on WordPress sites is facing active exploitation of CVE-2026-8181, a critical authentication bypass that can let unauthenticated attackers impersonate admins and create rogue accounts. The plugin is installed on about 200,000 sites, making the exposure broad. A fixed release, 3.4.2, is available, and defenders are being urged to update quickly.
Related Happenings
Funnel Builder plugin WordPress arbitrary JavaScript injection actively exploited security flaw
Vulnerability
H score72
First: 16.05.2026 18:20
Last: 16.05.2026 18:20
Sources 1
About this happening:
Funnel Builder for WordPress is under active exploitation for arbitrary JavaScript injection into WooCommerce checkout pages, creating payment-skimming risk across...
Funnel Builder plugin WordPress arbitrary JavaScript injection actively exploited security flaw
VulnerabilityAbout this happening: Funnel Builder for WordPress is under active exploitation for arbitrary JavaScript injection into WooCommerce checkout pages, creating payment-skimming risk across...
Nginx UI auth-bypass exploitation wave (CVE-2026-33032)
Exploitation Wave
H score9
First: 16.04.2026 01:35
Last: 16.04.2026 01:35
Sources 1
About this happening:
CVE-2026-33032 is now actively exploited, creating immediate risk for publicly exposed Nginx UI instances that rely on the vulnerable /mcp_message endpoint. Intern...
Nginx UI auth-bypass exploitation wave (CVE-2026-33032)
Exploitation WaveAbout this happening: CVE-2026-33032 is now actively exploited, creating immediate risk for publicly exposed Nginx UI instances that rely on the vulnerable /mcp_message endpoint. Intern...
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation Wave
H score79
First: 02.04.2026 11:25
Last: 02.04.2026 11:25
Sources 1
About this happening:
As of 2026-04-02, ongoing attacks are exploiting CVE-2025-53521 against F5 BIG-IP APM systems, leaving more than 14,000 exposed online and at risk of remote code e...
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation WaveAbout this happening: As of 2026-04-02, ongoing attacks are exploiting CVE-2025-53521 against F5 BIG-IP APM systems, leaving more than 14,000 exposed online and at risk of remote code e...
CISA KEV patch directive for CVE-2025-53521
Advisory/Mitigation
H score86
First: 30.03.2026 10:07
Last: 30.03.2026 10:07
Sources 1
About this happening:
CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...
CISA KEV patch directive for CVE-2025-53521
Advisory/MitigationAbout this happening: CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...
React2Shell (CVE-2025-55182) mass scanning and exploitation wave
Exploitation Wave
H score89
First: 20.02.2026 23:07
Last: 20.02.2026 23:07
Sources 1
About this happening:
CVE-2025-55182 (React2Shell) was publicly disclosed on December 3, 2025 as a CVSS 10 remote code execution flaw in React Server Components. Since then, the vulnera...
React2Shell (CVE-2025-55182) mass scanning and exploitation wave
Exploitation WaveAbout this happening: CVE-2025-55182 (React2Shell) was publicly disclosed on December 3, 2025 as a CVSS 10 remote code execution flaw in React Server Components. Since then, the vulnera...
Timeline
-
15.05.2026 00:07 1 articles · 2mo ago
CVE-2026-8181 introduced in Burst Statistics 3.4.0
Technical Analysis UpdateBurst Statistics version 3.4.0 introduced CVE-2026-8181 on April 23, and the same vulnerable code was also present in version 3.4.1, creating an authentication-bypass condition in the WordPress plugin's REST API authentication handling.
Show sources
- Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin — www.bleepingcomputer.com — 15.05.2026 00:07
-
15.05.2026 00:07 1 articles · 2mo ago
Wordfence discloses CVE-2026-8181
Initial DisclosureWordfence discovered CVE-2026-8181 on May 8 and described an authentication bypass that lets an unauthenticated attacker who knows a valid administrator username impersonate that administrator during REST API requests, with the worst case allowing a rogue administrator-level account to be created.
Show sources
- Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin — www.bleepingcomputer.com — 15.05.2026 00:07
-
15.05.2026 00:07 1 articles · 2mo ago
Burst Statistics 3.4.2 patch for CVE-2026-8181 released
Mitigation Patch UpdateA patched Burst Statistics release, version 3.4.2, was released on May 12, 2026, and site operators were told to upgrade or disable the plugin to remove CVE-2026-8181 exposure.
Show sources
- Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin — www.bleepingcomputer.com — 15.05.2026 00:07
-
15.05.2026 00:07 2 articles · 2mo ago
Wordfence tracks active exploitation of CVE-2026-8181
Exploitation ObservedWordfence's tracker showed over 7,400 blocked attacks targeting CVE-2026-8181 in the 24 hours before May 14, 2026, and the firm said malicious activity had already begun against Burst Statistics on WordPress sites.
Show sources
- Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin — www.bleepingcomputer.com — 15.05.2026 00:07
- Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin — www.bleepingcomputer.com — 15.05.2026 00:07