AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-11976

CRITICAL · CVSS 10 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The compromise of the MonsterInsights Pro update distribution bucket has resulted in the inclusion of a malicious file, `class-system-check.php`, in both the current and a previous version of the software. This vulnerability allows attackers to execute arbitrary code, potentially leading to full system compromise. Organizations using MonsterInsights Pro should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-11976
Severity
CRITICAL
CVSS
10
EPSS
0.49%

Original NVD Description

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.