← WordPress Vulnerabilities
WordPress security by component

monsterinsights

monsterinsights connects WordPress with Google Analytics and displays website traffic reports in the dashboard.

monsterinsights (monsterinsights) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 6.1.

Plugin slug: monsterinsights

CVE-2026-11366: MonsterInsights accepts forged empty-key configuration signatures

MonsterInsights before 11.1.0 validates an unauthenticated AJAX request with an HMAC key that is empty when the plugin is not connected to Google Analytics. An unauthenticated attacker can calculate a valid signature under that configuration and overwrite a MonsterInsights setting, disrupting server-side analytics in Manual GA4 mode. The public advisory does not disclose the AJAX action, signed fields, configuration parameter or update function.

PublishedAug 04, 2026
Known safe version11.1.0
Published vulnerabilities for monsterinsights
Safe version
Aug 04, 2026 CVE-2026-11366
MonsterInsights accepts forged empty-key configuration signatures
MonsterInsights before 11.1.0 validates an unauthenticated AJAX request with an HMAC key that is empty when the plugin is not connected to Google Analytics. An unauthenticated attacker can calculate a valid signature under that configuration and overwrite a MonsterInsights setting, disrupting server-side analytics in Manual GA4 mode. The public advisory does not disclose the AJAX action, signed fields, configuration parameter or update function.
11.1.0
CVE3.7
NVDPending
Feb 06, 2023 CVE-2023-0081
MonsterInsights: Cross-site scripting
MonsterInsights is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.4
NVD5.4
Jan 16, 2023 CVE-2022-3904
MonsterInsights: A security weakness
MonsterInsights is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.1
NVD6.1