CVE-2026-97343
Received Received - Intake

Improper Authentication in Burst Statistics WordPress Plugin

Vulnerability report for CVE-2026-97343, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: Wordfence

Description

The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, and including, 3.7.1. This is due to the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session cookie for the `burst_statistics_viewer` account to any visitor presenting a valid share token via `wp_set_auth_cookie()`, while the plugin only blocks Application Passwords for the resulting `burst_viewer` role and does not restrict the core `/wp-json/wp/v2/users/me` password update endpoint or filter the `edit_user` capability for that account β€” leaving WordPress core's built-in rule that any authenticated user may update their own account fully in effect. This makes it possible for unauthenticated attackers to set an attacker-chosen password on the `burst_statistics_viewer` WordPress account, constituting a permanent takeover of that limited-privilege (`view_burst_statistics`) account that persists through share-token revocation, share-token expiration, and execution of the plugin's daily `cleanup_viewer_sessions()` routine. Exploitation requires that the attacker have obtained a valid `burst_share_token`, such as one that has been shared publicly or distributed to an untrusted party.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wordfence burst_statistics to 3.7.1 (inc)
burst_statistics burst_statistics to 3.7.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Burst Statistics WordPress plugin allows unauthenticated attackers to set a password on the burst_statistics_viewer account by exploiting improper authentication. The plugin issues a WordPress session cookie to visitors with a valid share token but fails to restrict password updates for the resulting account. This leads to a permanent takeover of the limited-privilege account, even after share tokens are revoked or expire.

Detection Guidance

To detect this vulnerability, check for unauthorized password changes on the burst_statistics_viewer account. Inspect WordPress logs for requests to /wp-json/wp/v2/users/me or /wp-json/wp/v2/users/<id> with PUT or POST methods. Look for successful responses indicating password updates by unauthenticated users.

Impact Analysis

If you use the Burst Statistics plugin up to version 3.7.1, attackers could gain control of the burst_statistics_viewer account. This could allow them to access analytics data, modify settings, or perform actions within the limited privileges of that account. The impact persists even after share tokens are revoked.

Compliance Impact

This vulnerability could lead to unauthorized access to analytics data, potentially violating GDPR's data protection requirements or HIPAA's privacy rules if sensitive data is exposed. Unauthorized access to user data may result in non-compliance with these regulations.

Mitigation Strategies

Update the Burst Statistics plugin to the latest version beyond 3.7.1 to patch the authentication flaw. If an update is unavailable, consider disabling the plugin temporarily until a fix is released. Review WordPress user accounts for any unauthorized burst_statistics_viewer accounts and remove or reset their passwords immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97343. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart