Compromised Update Distribution for MonsterInsights Pro by MonsterInsights
CVE-2026-11976
Key Information:
- Vendor
MonsterInsights
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-11976?
The update distribution for MonsterInsights Pro was compromised, involving the presence of a malicious file named 'class-system-check.php' in both version 10.2.2 and the rolled-back version 10.2.0. This breach occurred through the official update bucket hosted on an Amazon S3 server. A single attacker was confirmed to have write access to the bucket and has released multiple variants of the malicious payload, utilizing the same AES-256-GCM key. This situation represents a significant risk for users relying on these versions, highlighting the need for immediate awareness and action.
Affected Version(s)
MonsterInsights Pro 10.2.0 < 11.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
