CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Called exploited the same day it was disclosed.
Measured from the CVE publication date to the earliest of 1 KEV catalogue that list it.
The life of this vulnerability
- CVE published
- First KEV listingsame day
- Last sighting4mo
Gaps are compressed to equal steps. The elapsed time is printed under each.
Which catalogues call it exploited
- CISA KEVUS federaldoes not list it
- EUVDENISA, European Uniondoes not list it
- VulnCheck KEVcommercial researchlisted May 14, 2026
- CIRCLaggregator, mirrors the abovedoes not list it
This rests on a single catalogue. No second catalogue corroborates the claim that it is being exploited. CIRCL is an aggregator and is not counted.
Public exploitation evidence
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-8
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-8
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-8
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-8
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-8
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-8
19 public reports collected from VulnCheck and CIRCL, first on May 14, 2026. Each links to its original source. We have not verified them.
Description
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the request by supplying any random Basic Authentication password achieving privilege escalation.