WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。WordPress plugin是一个应用插件。 WordPress plugin Burst Statistics – Privacy-Friendly WordPress Analytics 3.4.0版本至3.4.1.1版本存在授权问题漏洞,该漏洞源于is_mainwp_authenticat
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| burstbv | Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) | 3.4.0≤ 3.4.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| burstbv | Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) | 3.4.0 ~ 3.4.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Burst Statistics – Privacy-Friendly WordPress Analytics plugin 3.4.0 to 3.4.1.1 contains an authentication bypass caused by incorrect return-value handling in is_mainwp_authenticated() function, letting unauthenticated attackers impersonate administrators, exploit requires knowledge of an administrator username. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-8181.yaml | POC Details |
No comments yet