plugin

Burst Statistics Vulnerabilities

9 known security issues reported for the Burst Statistics WordPress plugin. Most recent disclosed May 13, 2026.

2 critical 1 high 2 medium

Running Burst Statistics on your site? Check whether your installed version is affected.

Scan your site free

Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

critical

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the A...

CVSS:
9.8
Affected:
3.4.0 – 3.4.1.1
Fixed in:
3.4.2
Disclosed:
May 13, 2026

CVE-2026-8181 on NVD →

Burst Statistics <= 2.0.6 - Cross-Site Request Forgery

medium

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorize...

CVSS:
4.3
Affected:
up to 2.0.6
Fixed in:
2.0.8
Disclosed:
Jun 27, 2025

CVE-2025-53193 on NVD →

Burst Statistics &#8211; Privacy-Friendly Analytics for WordPress [burst-statistics] < 2.0.8

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Burst Statistics B.V. Burst Statistics allows Cross Site Request Forgery. This issue affects Burst Statistics: from n/a through 2.0.6.

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Jun 27, 2025

CVE-2025-53193 on NVD →

Burst Statistics &#8211; Privacy-Friendly Analytics for WordPress [burst-statistics] < 1.5.7

unknown

[en] The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'burst_total_pageviews_count' custom meta field in all versions up to, and including, 1.5.6.1 due to insufficient input sanitization and output escaping on user supplied attribu...

Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Mar 13, 2024

CVE-2024-1894 on NVD →

Burst Statistics – Privacy-Friendly Analytics for WordPress <= 1.5.6.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via burst_total_pageviews_count

medium

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'burst_total_pageviews_count' custom meta field in all versions up to, and including, 1.5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes....

CVSS:
6.4
Affected:
up to 1.5.6.1
Fixed in:
1.5.7
Disclosed:
Mar 12, 2024

CVE-2024-1894 on NVD →

Burst Statistics &#8211; Privacy-Friendly Analytics for WordPress [burst-statistics] < 1.5.4

unknown

[en] The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id', 'page_url', 'platform', and 'referrer'. T...

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Jan 17, 2024

CVE-2024-0405 on NVD →

Burst Statistics Really Simple Plugins <= 1.5.3 - Authenticated (Editor+) SQL Injection

high

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id', 'page_url', 'platform', and 'referrer'. This v...

CVSS:
7.2
Affected:
up to 1.5.3
Fixed in:
1.5.4
Disclosed:
Jan 16, 2024

CVE-2024-0405 on NVD →

Burst Statistics &#8211; Privacy-Friendly Analytics for WordPress [burst-statistics] < 1.5.0

unknown

[en] The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exi...

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Dec 7, 2023

CVE-2023-5761 on NVD →

Burst Statistics – Privacy-Friendly Analytics for WordPress 1.4.0 to 1.4.6.1 - Unauthenticated SQL Injection

critical

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...

CVSS:
9.8
Affected:
1.4.0 – 1.4.6.1
Fixed in:
1.5.0
Disclosed:
Dec 6, 2023

CVE-2023-5761 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database