LIVE · cybersecurity feed
Live wire
cve recordcriticalzero dayexploit reported

CVE-2026-8181

Published
CVSS9.8
Severitycritical
WeaknessCWE-287
EPSS14.6%96.4th percentile
Exploited1 KEV source

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

patch window

Called exploited the same day it was disclosed.

Measured from the CVE publication date to the earliest of 1 KEV catalogue that list it.

The life of this vulnerability

  1. CVE published
  2. First KEV listingsame day
  3. Last sighting4mo

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources1 of 3
Listings differ by

This rests on a single catalogue. No second catalogue corroborates the claim that it is being exploited. CIRCL is an aggregator and is not counted.

Public exploitation evidence

19 public reports collected from VulnCheck and CIRCL, first on May 14, 2026. Each links to its original source. We have not verified them.

Description

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the request by supplying any random Basic Authentication password achieving privilege escalation.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-8181

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-8181.