Impact
The MonsterInsights WordPress plugin before version 11.1.0 does not validate the HMAC signature on a specific unauthenticated AJAX action. The flaw (CWE‑287) allows an attacker to forge a valid signature when the plugin is not connected to Google Analytics, enabling the attacker to overwrite a configuration value used for Manual GA4 mode and thereby disabling the plugin’s server‑side analytics functionality.
Affected Systems
All installations of the MonsterInsights plugin older than 11.1.0 are affected regardless of the WordPress version. Only the MonsterInsights plugin is impacted; no other vendor or product is involved.
Risk and Exploitability
The issue is exploitable with unauthenticated HTTP requests to the plugin’s AJAX endpoint, so the attack surface is wide. The CVSS score of 3.7 indicates a low impact for configuration change. The EPSS score is less than 1 percent and the vulnerability is not listed in the CISA KEV catalogue, implying no publicly documented exploits to date. Nonetheless the ability to change configuration without authentication remains a risk for sites relying on MonsterInsights for analytics.
OpenCVE Enrichment