CVE-2026-97343: CWE-287 Improper Authentication in burstbv Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)
The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, and including, 3.7.1. This is due to the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session cookie for the `burst_statistics_viewer` account to any visitor presenting a valid share token via `wp_set_auth_cookie()`, while the plugin only blocks Application Passwords for the resulting `burst_viewer` role and does not restrict the core `/wp-json/wp/v2/users/me` password update endpoint or filter the `edit_user` capability for that account — leaving WordPress core's built-in rule that any authenticated user may update their own account fully in effect. This makes it possible for unauthenticated attackers to set an attacker-chosen password on the `burst_statistics_viewer` WordPress account, constituting a permanent takeover of that limited-privilege (`view_burst_statistics`) account that persists through share-token revocation, share-token expiration, and execution of the plugin's daily `cleanup_viewer_sessions()` routine. Exploitation requires that the attacker have obtained a valid `burst_share_token`, such as one that has been shared publicly or distributed to an untrusted party.
AI Analysis
Technical Summary
CVE-2026-97343 describes an improper authentication vulnerability in the Burst Statistics – Simple WordPress Analytics plugin for WordPress versions up to 3.7.1. The vulnerability arises from the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session cookie for the `burst_statistics_viewer` account to any visitor presenting a valid share token via `wp_set_auth_cookie()`. The plugin only blocks Application Passwords for this role but does not restrict the core WordPress `/wp-json/wp/v2/users/me` password update endpoint or filter the `edit_user` capability. Since WordPress allows any authenticated user to update their own account, an attacker with a valid share token can set an attacker-chosen password on the `burst_statistics_viewer` account, resulting in permanent account takeover that persists through token revocation, expiration, and session cleanup.
Potential Impact
An attacker who obtains a valid burst share token can permanently take over the 'burst_statistics_viewer' WordPress account, which has limited privileges to view burst statistics. This takeover allows the attacker to maintain persistent access despite revocation or expiration of the share token and routine session cleanup. The vulnerability does not impact confidentiality but allows integrity compromise of the viewer account through unauthorized password changes.
Mitigation Recommendations
No official patch or fix is currently documented. Users should treat any publicly shared or distributed burst share tokens as sensitive and revoke or rotate them if possible. Monitor vendor advisories for updates or patches addressing this vulnerability. Until a fix is available, restrict distribution of share tokens to trusted parties only.
CVE-2026-97343: CWE-287 Improper Authentication in burstbv Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)
Description
The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, and including, 3.7.1. This is due to the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session cookie for the `burst_statistics_viewer` account to any visitor presenting a valid share token via `wp_set_auth_cookie()`, while the plugin only blocks Application Passwords for the resulting `burst_viewer` role and does not restrict the core `/wp-json/wp/v2/users/me` password update endpoint or filter the `edit_user` capability for that account — leaving WordPress core's built-in rule that any authenticated user may update their own account fully in effect. This makes it possible for unauthenticated attackers to set an attacker-chosen password on the `burst_statistics_viewer` WordPress account, constituting a permanent takeover of that limited-privilege (`view_burst_statistics`) account that persists through share-token revocation, share-token expiration, and execution of the plugin's daily `cleanup_viewer_sessions()` routine. Exploitation requires that the attacker have obtained a valid `burst_share_token`, such as one that has been shared publicly or distributed to an untrusted party.
CVSS v3.1
Score 4.3medium
Affected software
burstbv
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-97343 describes an improper authentication vulnerability in the Burst Statistics – Simple WordPress Analytics plugin for WordPress versions up to 3.7.1. The vulnerability arises from the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session cookie for the `burst_statistics_viewer` account to any visitor presenting a valid share token via `wp_set_auth_cookie()`. The plugin only blocks Application Passwords for this role but does not restrict the core WordPress `/wp-json/wp/v2/users/me` password update endpoint or filter the `edit_user` capability. Since WordPress allows any authenticated user to update their own account, an attacker with a valid share token can set an attacker-chosen password on the `burst_statistics_viewer` account, resulting in permanent account takeover that persists through token revocation, expiration, and session cleanup.
Potential Impact
An attacker who obtains a valid burst share token can permanently take over the 'burst_statistics_viewer' WordPress account, which has limited privileges to view burst statistics. This takeover allows the attacker to maintain persistent access despite revocation or expiration of the share token and routine session cleanup. The vulnerability does not impact confidentiality but allows integrity compromise of the viewer account through unauthorized password changes.
Mitigation Recommendations
No official patch or fix is currently documented. Users should treat any publicly shared or distributed burst share tokens as sensitive and revoke or rotate them if possible. Monitor vendor advisories for updates or patches addressing this vulnerability. Until a fix is available, restrict distribution of share tokens to trusted parties only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-09-24T12:25:02.165Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac0abd7a43b0b3b89a7e7d6
Added to database: 10/03/2026, 07:16:39 UTC
Last enriched: 10/03/2026, 07:31:36 UTC
Last updated: 10/04/2026, 02:48:53 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.