Improper Authentication Vulnerability in Burst Statistics Plugin for WordPress
CVE-2026-97343
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-97343?
The Burst Statistics plugin for WordPress is susceptible to an improper authentication issue that may lead to account persistence. This vulnerability stems from the maybe_load_shared_dashboard() function, which erroneously grants a WordPress session cookie to any visitor who presents a valid share token. This oversight allows unauthorized users to exploit the system, potentially taking control of the burst_statistics_viewer account by setting their own password. The attack can persist even after revocation of the share token or execution of cleanup routines, permitting long-term control of the application with limited privileges. To exploit this vulnerability, an attacker must obtain a valid burst_share_token, making it crucial for users to be vigilant about how these tokens are shared.
Affected Version(s)
Burst Statistics β Simple WordPress Analytics (Google Analytics Alternative) 0 <= 3.7.1