AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-11366

LOW · CVSS 3.7 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The MonsterInsights WordPress plugin prior to version 11.1.0 is vulnerable due to improper validation of the HMAC signature on unauthenticated AJAX actions, allowing attackers to forge valid signatures. This flaw can lead to unauthorized configuration changes, potentially disrupting server-side analytics when the plugin is not connected to Google Analytics. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-11366
Severity
LOW
CVSS
3.7
EPSS
0.15%
WordPress

Original NVD Description

The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.