Sceawere
Vulnerability Detail
CVE-2026-97343UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Burst Statistics Account Persistence Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- burstbv
- Product
- Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, and including, 3.7.1. This is due to the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session cookie for the `burst_statistics_viewer` account to any visitor presenting a valid share token via `wp_set_auth_cookie()`, while the plugin only blocks Application Passwords for the resulting `burst_viewer` role and does not restrict the core `/wp-json/wp/v2/users/me` password update endpoint or filter the `edit_user` capability for that account — leaving WordPress core's built-in rule that any authenticated user may update their own account fully in effect. This makes it possible for unauthenticated attackers to set an attacker-chosen password on the `burst_statistics_viewer` WordPress account, constituting a permanent takeover of that limited-privilege (`view_burst_statistics`) account that persists through share-token revocation, share-token expiration, and execution of the plugin's daily `cleanup_viewer_sessions()` routine. Exploitation requires that the attacker have obtained a valid `burst_share_token`, such as one that has been shared publicly or distributed to an untrusted party.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-03T07:16:49.363Z",
"pubdate": "2026-10-03T07:16:49.363Z",
"executiveSummary": "The Burst Statistics – Simple WordPress Analytics plugin (up to version 3.7.1) contains an improper authentication flaw that allows for permanent account persistence. The vulnerability originates from the plugin's share-token authentication mechanism, which grants a full WordPress session to an unprivileged viewer account.\nBecause the plugin fails to restrict standard WordPress user profile management endpoints for the 'burst_statistics_viewer' account, an attacker possessing a valid share token can perform a full account takeover. By exploiting the core WordPress 'edit_user' capability—which permits users to update their own credentials—an attacker can change the account password. This results in the attacker gaining permanent, authenticated access to the system that persists even after the original share token expires or is revoked. This vulnerability poses a significant risk to site integrity, as it enables unauthorized persistence within the WordPress environment, bypassing the intended limitations of the plugin's restricted viewer role.",
"technicalDetails": "The vulnerability resides in the 'maybe_load_shared_dashboard()' function within the Burst Statistics plugin. The function is designed to facilitate access to analytics reports by granting a valid WordPress session to users presenting a legitimate 'burst_share_token'.\nWhen a request containing a valid token is processed, the plugin calls 'wp_set_auth_cookie()', effectively authenticating the visitor as the 'burst_statistics_viewer' user. While the plugin implements restrictive logic to block Application Passwords for this role, it fails to implement necessary filters on the underlying WordPress core API endpoints.\nSpecifically, the plugin does not restrict the 'wp_update_user' flow or the '/wp-json/wp/v2/users/me' REST API endpoint. In WordPress, any authenticated user possesses the implicit capability to update their own account profile, including the email address and password, provided the system does not explicitly restrict this action via a capability filter.\nThe exploitation process follows this sequence: 1) An attacker obtains a valid 'burst_share_token' that has been exposed or shared. 2) The attacker navigates to the target site with the token, triggering the 'maybe_load_shared_dashboard()' function, which sets a persistent 'burst_statistics_viewer' authentication cookie. 3) Now authenticated as a WordPress user, the attacker accesses the core '/wp-json/wp/v2/users/me' endpoint. 4) The attacker issues a POST request to update the account password to a value of their choosing. 5) Once the password is changed, the account is decoupled from the transient share-token mechanism. The attacker now maintains permanent access to this account regardless of the plugin's 'cleanup_viewer_sessions()' routine, share token expiration, or token revocation.\nThe post-exploitation impact includes unauthorized authenticated access to the WordPress backend. Although the 'burst_statistics_viewer' account is intended to have limited permissions (e.g., 'view_burst_statistics'), persistent access provides a foothold for further exploitation, such as probing for additional vulnerabilities, accessing sensitive analytics data, or utilizing the authenticated session to bypass WAF rules or other perimeter security controls."
}