Impact
The Vulnerable WordPress analytics plugin issues a genuine WordPress session cookie for the "burst_statistics_viewer" account when a visitor presents a valid "burst_share_token". The plugin disables application passwords for the resulting "burst_viewer" role but does not protect the core user update endpoints. Consequently, an attacker who obtains a share token can set an arbitrary password for the limited‑privilege account, achieving permanent ownership of that account regardless of token revocation, expiration, or normal cleanup. This results in sustained credential compromise and potential lateral movement if the view rights are leveraged for further attacks.
Affected Systems
Burst bv's "Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)" plugin for WordPress. All versions up to and including 3.7.1 are vulnerable; versions 3.7.2 and newer are presumed fixed based on repository references.
Risk and Exploitability
The vulnerability scores a CVSS of 4.3, indicating moderate severity. EPSS data is unavailable, and the issue is not listed in CISA KEV. Exploitation requires access to a valid share token, which may be publicly disclosed or distributed to untrusted parties. An unauthenticated attacker with such a token can hijack the viewer account, leading to permanent compromise of that account even if the token is later revoked.
OpenCVE Enrichment