🔐 CVE Alert

CVE-2026-11366

UNKNOWN 0.0

MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.

Vendor unknown
Product monsterinsights
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown monsterinsights

Be the first to know when new unknown vulnerabilities affecting unknown monsterinsights are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / MonsterInsights
0 < 11.1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/283331ca-cc2e-4c2c-9e3b-2e8c6f0c84d2/

Credits

Đặng Tiến Dũng WPScan