目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-97343— Burst Statistics 3.7.1 及之前版本 身份验证绕过漏洞

一分钟漏洞结论

影响对象
burstbv Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

WordPress 插件 “Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)” 在所有 3.7.1 及以下版本中存在身份验证不当(Improper Authentication)漏洞,可导致账户持久化(Account Persistence)。 该漏洞的成因在于: 处理函数通过调用 ,为任何提供有效共享令牌(share token)的访客授予一个真实的 WordPress 会话 cookie,并将其分配给 账户。

CVSS 4.3 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-97343 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link Authentication Bypass via 'burst_share_token'
来源: CVE Program / CVE List V5
Vulnerability Description
The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, and including, 3.7.1. This is due to the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session cookie for the `burst_statistics_viewer` account to any visitor presenting a valid share token via `wp_set_auth_cookie()`, while the plugin only blocks Application Passwords for the resulting `burst_viewer` role and does not restrict the core `/wp-json/wp/v2/users/me` password update endpoint or filter the `edit_user` capability for that account — leaving WordPress core's built-in rule that any authenticated user may update their own account fully in effect. This makes it possible for unauthenticated attackers to set an attacker-chosen password on the `burst_statistics_viewer` WordPress account, constituting a permanent takeover of that limited-privilege (`view_burst_statistics`) account that persists through share-token revocation, share-token expiration, and execution of the plugin's daily `cleanup_viewer_sessions()` routine. Exploitation requires that the attacker have obtained a valid `burst_share_token`, such as one that has been shared publicly or distributed to an untrusted party.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
burstbv Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) 0 ~ 3.7.1 -

二、漏洞 CVE-2026-97343 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-97343 的情报信息

请登录查看更多情报信息。

CVE-2026-97343 其他参考 (7)

IV. Related Vulnerabilities

V. Comments for CVE-2026-97343

暂无评论


发表评论