t threatover

Blog

Notes from the cleanup floor

Field notes, incident retrospectives, and short reads on WordPress malware and site recovery.

Site owner 2 min read

Burst Statistics auth bypass (CVE-2026-8181): exploited in the wild

A 9.8 CVSS authentication bypass in the Burst Statistics plugin is being exploited. 200K+ sites affected. Here's a quick triage.

Read article →

Accepting engagements

Site compromised? Let's talk.

Send us what you know. You get a triage and a fixed quote in return.

Open intake form →