Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-11976: MonsterInsights Pro update distribution compromised, malicious files uploaded

CVE-2026-11976 · published 29 days ago
Summary

The official update distribution for MonsterInsights Pro has been compromised. This means that if you've updated your website recently, you may have inadvertently installed a malicious file. We recommend immediately removing any updates to MonsterInsights Pro and checking with your web developer to ensure your site is secure.

What to do
  • Update unknown monsterinsights pro to version 11.0.0 or later.
Affected software
VendorProductAffected versions
unknown monsterinsights pro < 11.0.0
Original advisory text
MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-912Hidden Functionality
Timeline
Published6 Aug 2026
Updated3 Sep 2026
First seen6 Aug 2026
Sources
CVE-2026-11976 · MITRE
Monitor software like this
Free during beta