Impact
The MonsterInsights plugin contains missing capability checks on the get_ads_access_token() and reset_experience() functions in all versions up to 10.1.2. This flaw allows an authenticated attacker with Subscriber level or higher to retrieve live Google OAuth access tokens and reset the plugin's Google Ads integration. The vulnerability falls under CWE-862, indicating an access control issue that can expose credentials and alter integration settings.
Affected Systems
All installations of the MonsterInsights – Google Analytics Dashboard for WordPress plugin v10.1.2 or earlier, running on WordPress.
Risk and Exploitability
The CVSS score is 7.1, indicating a medium to high severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is authenticated; an attacker must possess at least Subscriber role permissions to exploit the flaw. Once compromised, the attacker can obtain OAuth tokens, potentially accessing Google Analytics data and reorganizing the Google Ads integration.
OpenCVE Enrichment