WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Burst Statistics safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Burst Statistics WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: burst-statistics

Maintenance status

Known vulnerabilities

5 known CVEs on file for Burst Statistics. Reported between 2023 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8181 Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 3.4.2 Improper Authentication Critical 9.8 < 3.4.2 3.4.2 2026-05-13
CVE-2025-53193 Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 2.0.8 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.0.8 2.0.8 2025-06-27
CVE-2024-1894 Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.5.7 1.5.7 2024-03-12
CVE-2024-0405 Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 1.5.4 1.5.4 2024-01-16
CVE-2023-5761 Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 1.5.0 1.5.0 2023-12-06

CVE-2026-8181

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the request by supplying any random Basic Authentication password achieving privilege escalation.

Source: CVE.org

CVE-2025-53193

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

CVE-2024-1894

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'burst_total_pageviews_count' custom meta field in all versions up to, and including, 1.5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that this exploit only functions if the victim has the 'Show Toolbar when viewing site' option enabled in their profile.

Source: CVE.org

CVE-2024-0405

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id', 'page_url', 'platform', and 'referrer'. This vulnerability arises due to insufficient escaping of user-supplied parameters and the lack of adequate preparation in SQL queries. As a result, authenticated attackers with editor access or higher can append additional SQL queries into existing ones, potentially leading to unauthorized access to sensitive information from the database.

Source: CVE.org

CVE-2023-5761

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: CVE.org

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.