PT-2026-104550 · WordPress · Burst Statistics

·

CVE-2026-97343

·

Published

2026-10-03

·

Updated

2026-10-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) versions prior to 3.7.2
Description Improper authentication allows for account persistence. The maybe load shared dashboard() handler issues a genuine WordPress session cookie for the burst statistics viewer account to visitors providing a valid share token via wp set auth cookie(). Because the plugin does not restrict the /wp-json/wp/v2/users/me password update endpoint or filter the edit user capability for this account, unauthenticated attackers with a valid burst share token can set a custom password for the burst statistics viewer account. This results in a permanent takeover of the limited-privilege account that persists even after share-token revocation, expiration, or the execution of the cleanup viewer sessions() function.
Recommendations Update Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) to version 3.7.2 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97343

Affected Products

Burst Statistics