Known vulnerabilities in Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)
Simple, lightweight WordPress analytics with privacy-friendly visitor tracking. Cookieless and GDPR-ready. Setup in seconds, no cookie banner needed.
5Reported vulnerabilities
9.8Highest CVSS score
3.6.2Latest version
200,000+Active installs
What to do now
Update Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) to 3.4.2 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-8181 | Critical | 14.6% | 3.4.0 to 3.4.1.1 (inclusive) | 3.4.2 |
May 14, 2026 |
| CVE-2023-5761 | High | 0.7% | 1.4.0 up to (but not including) 1.5.0 | 1.5.0 |
December 7, 2023 |
| CVE-2024-0405 | Medium | 0.6% | Before 1.5.3 | 1.5.3 |
January 17, 2024 |
| CVE-2024-1894 | Medium | 0.5% | Before 1.5.7 | 1.5.7 |
March 13, 2024 |
| CVE-2025-53193 | Medium | 0.1% | 2.0.6 and earlier | 2.0.8 |
June 27, 2025 |