PT-2026-104550 · WordPress · Burst Statistics
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) versions prior to 3.7.2
Description
Improper authentication allows for account persistence. The
maybe load shared dashboard() handler issues a genuine WordPress session cookie for the burst statistics viewer account to visitors providing a valid share token via wp set auth cookie(). Because the plugin does not restrict the /wp-json/wp/v2/users/me password update endpoint or filter the edit user capability for this account, unauthenticated attackers with a valid burst share token can set a custom password for the burst statistics viewer account. This results in a permanent takeover of the limited-privilege account that persists even after share-token revocation, expiration, or the execution of the cleanup viewer sessions() function.Recommendations
Update Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) to version 3.7.2 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Burst Statistics