CVE Explorer
CVE-2026-8181
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the re
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)","vendor":"burstbv","versions":[{"lessThanOrEqual":"3.4.1.1","status":"affected","version":"3.4.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-287","description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/problemTypes/0/descriptions/0
Source references
10 source assertions{"url":"https://github.com/Burst-Statistics/burst-statistics/blob/2488d3fa54045e7e5342b0445b9f6b5eaac9ea7c/includes/Frontend/class-mainwp-proxy.php#L385"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/9
{"url":"https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.4.1.1/includes/Frontend/class-mainwp-proxy.php#L314"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/6
{"url":"https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.4.1.1/includes/Frontend/class-mainwp-proxy.php#L328"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/4
{"url":"https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.4.1.1/includes/Frontend/class-mainwp-proxy.php#L336"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/1
{"url":"https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.4.1.1/includes/Traits/trait-admin-helper.php#L205"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/8
{"url":"https://plugins.trac.wordpress.org/browser/burst-statistics/trunk/includes/Frontend/class-mainwp-proxy.php#L314"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/5
{"url":"https://plugins.trac.wordpress.org/browser/burst-statistics/trunk/includes/Frontend/class-mainwp-proxy.php#L328"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/3
{"url":"https://plugins.trac.wordpress.org/browser/burst-statistics/trunk/includes/Frontend/class-mainwp-proxy.php#L336"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/2
{"url":"https://plugins.trac.wordpress.org/browser/burst-statistics/trunk/includes/Traits/trait-admin-helper.php#L205"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/7
{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ca830d6-3d3c-4026-85cd-8447b8a568d3?source=cve"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:378b58b3928e24bac08fd1b158317cd3a335ae1a33498fbb4714907bb73242b2 · sha256:caf56ca48dd8afdb… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.