Resources /
WordPress Plugins /
Burst Statistics
PLUGIN SECURITY
Is Burst Statistics safe?
Known vulnerabilities, PHP compatibility and safer alternatives for the Burst Statistics WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
Maintenance status
Known vulnerabilities
5 known CVEs on file for Burst Statistics.
Reported between 2023 and 2026.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-8181
|
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 3.4.2 |
Improper Authentication |
Critical
9.8
|
< 3.4.2
|
3.4.2 |
2026-05-13 |
—
|
|
CVE-2025-53193
|
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 2.0.8 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 2.0.8
|
2.0.8 |
2025-06-27 |
—
|
|
CVE-2024-1894
|
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.7 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 1.5.7
|
1.5.7 |
2024-03-12 |
—
|
|
CVE-2024-0405
|
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.4 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Medium
6.5
|
< 1.5.4
|
1.5.4 |
2024-01-16 |
—
|
|
CVE-2023-5761
|
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.0 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.5
|
< 1.5.0
|
1.5.0 |
2023-12-06 |
—
|
CVE-2026-8181
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the request by supplying any random Basic Authentication password achieving privilege escalation.
Source:
CVE.org
CVE-2025-53193
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
CVE-2024-1894
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'burst_total_pageviews_count' custom meta field in all versions up to, and including, 1.5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that this exploit only functions if the victim has the 'Show Toolbar when viewing site' option enabled in their profile.
Source:
CVE.org
CVE-2024-0405
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id', 'page_url', 'platform', and 'referrer'. This vulnerability arises due to insufficient escaping of user-supplied parameters and the lack of adequate preparation in SQL queries. As a result, authenticated attackers with editor access or higher can append additional SQL queries into existing ones, potentially leading to unauthorized access to sensitive information from the database.
Source:
CVE.org
CVE-2023-5761
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
CVE.org
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.