CVE-2026-11976
Received Received - Intake

Malicious Code Injection in MonsterInsights Pro

Vulnerability report for CVE-2026-11976, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
monsterinsights monsterinsights_pro to 10.2.2 (inc)
monsterinsights monsterinsights_pro to 10.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability involves a compromised official MonsterInsights Pro update bucket on AWS S3. The attacker injected a malicious file named class-system-check.php into legitimate plugin versions 10.2.2 and 10.2.0. The same encryption key was used across three variants, indicating a single threat actor with ongoing access to the bucket.

Detection Guidance

Check for the presence of the malicious file class-system-check.php in your MonsterInsights Pro installation directory. Verify file integrity by comparing hashes of installed files against known good versions from official sources.

Impact Analysis

If you installed or updated MonsterInsights Pro during the compromise period, your site may have downloaded the malicious file. This could allow attackers to execute arbitrary code on your server, potentially leading to full system compromise, data theft, or further malware distribution.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and security. GDPR and HIPAA mandate safeguards against unauthorized code execution and data breaches. The compromise could result in unauthorized access to user data, triggering mandatory breach notifications and potential fines.

Mitigation Strategies

Immediately remove MonsterInsights Pro from your system. Revoke any AWS S3 bucket access associated with MonsterInsights. Monitor for unauthorized access or modifications to your WordPress installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11976. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart