Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A critical authentication bypass in the Burst Statistics WordPress plugin (versions 3.4.0 and 3.4.1) allows any unauthenticated attacker to create administrator accounts and take full control of affected sites. Approximately 115,000 of the plugin’s 200,000 active installs remain unpatched as of May 14, 2026. Exploitation at scale is confirmed, with threat intelligence indicating significant attack volume in the 24 hours following public disclosure. Organizations running WordPress sites with this plugin face complete site compromise, including data theft, defacement, and malware deployment, until the patch is applied.

Author

Tech Jacks Solutions