Improper Authentication Vulnerability in Burst Statistics Plugin for WordPress
CVE-2026-97343

4.3MEDIUM

What is CVE-2026-97343?

The Burst Statistics plugin for WordPress is susceptible to an improper authentication issue that may lead to account persistence. This vulnerability stems from the maybe_load_shared_dashboard() function, which erroneously grants a WordPress session cookie to any visitor who presents a valid share token. This oversight allows unauthorized users to exploit the system, potentially taking control of the burst_statistics_viewer account by setting their own password. The attack can persist even after revocation of the share token or execution of cleanup routines, permitting long-term control of the application with limited privileges. To exploit this vulnerability, an attacker must obtain a valid burst_share_token, making it crucial for users to be vigilant about how these tokens are shared.

Affected Version(s)

Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) 0 <= 3.7.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

crow
.