Description
The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.
Published: 2026-08-04
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MonsterInsights WordPress plugin before version 11.1.0 does not validate the HMAC signature on a specific unauthenticated AJAX action. The flaw (CWE‑287) allows an attacker to forge a valid signature when the plugin is not connected to Google Analytics, enabling the attacker to overwrite a configuration value used for Manual GA4 mode and thereby disabling the plugin’s server‑side analytics functionality.

Affected Systems

All installations of the MonsterInsights plugin older than 11.1.0 are affected regardless of the WordPress version. Only the MonsterInsights plugin is impacted; no other vendor or product is involved.

Risk and Exploitability

The issue is exploitable with unauthenticated HTTP requests to the plugin’s AJAX endpoint, so the attack surface is wide. The CVSS score of 3.7 indicates a low impact for configuration change. The EPSS score is less than 1 percent and the vulnerability is not listed in the CISA KEV catalogue, implying no publicly documented exploits to date. Nonetheless the ability to change configuration without authentication remains a risk for sites relying on MonsterInsights for analytics.

Generated by OpenCVE AI on August 4, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MonsterInsights plugin to version 11.1.0 or later, which validates the HMAC key for all requests.
  • If an upgrade is not possible, disable the unauthenticated AJAX endpoint that modifies configuration until the plugin is updated.
  • Restrict configuration changes to authenticated users and monitor the plugin’s logs for unauthorized writes.

Generated by OpenCVE AI on August 4, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-327

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-327

Tue, 04 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Monsterinsights
Monsterinsights monsterinsights
Wordpress
Wordpress wordpress
Vendors & Products Monsterinsights
Monsterinsights monsterinsights
Wordpress
Wordpress wordpress

Tue, 04 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.
Title MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass
References

Subscriptions

Monsterinsights Monsterinsights
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T14:33:12.162Z

Reserved: 2026-06-05T11:55:39.062Z

Link: CVE-2026-11366

cve-icon Vulnrichment

Updated: 2026-08-04T14:32:45.480Z

cve-icon NVD

Status : Received

Published: 2026-08-04T07:16:28.370

Modified: 2026-08-04T15:16:24.397

Link: CVE-2026-11366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:45:02Z

Weaknesses