Description
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.
Published: 2026-08-06
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MonsterInsights Pro distributed itself from an official AWS S3 bucket that was compromised, allowing an attacker to insert a malicious PHP file named class‑system‑check.php into the plugin package. When a WordPress site downloads or updates the plugin from that bucket, the plugin contains the injected file. The file is executed within the plugin's context, giving the attacker the potential to run arbitrary PHP code, read and modify site data, and fully control the WordPress installation. The exact capabilities of the file are not disclosed, but its presence in the update package subjects any site that installed or updated the affected releases to the same risk.

Affected Systems

WordPress installations that use MonsterInsights Pro version 10.2.0 or 10.2.2, or that have installed a plugin update from the compromised product distribution bucket, are affected. Any user who has installed or updated the plugin between its 10.2.0, 10.2.2 releases during the attack window should verify that the plugin files are clean.

Risk and Exploitability

This vulnerability carries a CVSS score of 10, indicating critical impact. Its EPSS score of less than 1% suggests that the likelihood of exploitation by the broader community is currently very low, and it is not listed in the CISA KEV catalog. However, an active threat actor has repeatedly iterated on the payload, and the known supply‑chain compromise provides a very direct attack path: automatic or manual download of the plugin package from the infiltrated bucket delivers the malicious file to the site. The CWE-912 weakness indicates that improper validation during the application or component loading process enables this type of code injection.

Generated by OpenCVE AI on August 7, 2026 at 17:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install MonsterInsights Pro from a verified, non‑compromised source after removing the existing installation
  • Delete any file named class‑system‑check.php (or other unknown PHP files) from the plugin directory
  • Verify the integrity of all plugin files against known good hashes and temporarily disable automatic updates for MonsterInsights Pro until the distribution channel is secured

Generated by OpenCVE AI on August 7, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Monsterinsights
Monsterinsights monsterinsights
Vendors & Products Monsterinsights
Monsterinsights monsterinsights

Fri, 07 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-730

Fri, 07 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-912
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-730

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.
Title MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Monsterinsights Monsterinsights
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T13:47:29.290Z

Reserved: 2026-06-11T12:56:22.681Z

Link: CVE-2026-11976

cve-icon Vulnrichment

Updated: 2026-08-07T13:47:15.354Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T22:16:45.103

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-11976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:49Z

Weaknesses