← العودة للجدول
CVE-2026-8181
CVE-2026-8181 — The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics
📅 2026-05-14
🔴 Critical 🔥 No NVD ICS/OT OT/ICS CVSS 9.8 🎯 EPSS 4.73%

📋 الوصف الكامل

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, wit

💻 الأنظمة المتأثرة

Microsoft Edge | WordPress

⚠️ نوع التهديد

ICS/OT

🔗 CVE ID

CVE-2026-8181

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v3.4.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←