monsterinsights
monsterinsights connects WordPress with Google Analytics and displays website traffic reports in the dashboard.
monsterinsights (monsterinsights) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 6.1.
monsterinsightsCVE-2026-11366: MonsterInsights accepts forged empty-key configuration signatures
MonsterInsights before 11.1.0 validates an unauthenticated AJAX request with an HMAC key that is empty when the plugin is not connected to Google Analytics. An unauthenticated attacker can calculate a valid signature under that configuration and overwrite a MonsterInsights setting, disrupting server-side analytics in Manual GA4 mode. The public advisory does not disclose the AJAX action, signed fields, configuration parameter or update function.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-11366
MonsterInsights accepts forged empty-key configuration signatures
MonsterInsights before 11.1.0 validates an unauthenticated AJAX request with an HMAC key that is empty when the plugin is not connected to Google Analytics. An unauthenticated attacker can calculate a valid signature under that configuration and overwrite a MonsterInsights setting, disrupting server-side analytics in Manual GA4 mode. The public advisory does not disclose the AJAX action, signed fields, configuration parameter or update function.
|
11.1.0 |
CVE3.7
NVDPending
|
| Feb 06, 2023 |
CVE-2023-0081
MonsterInsights: Cross-site scripting
MonsterInsights is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jan 16, 2023 |
CVE-2022-3904
MonsterInsights: A security weakness
MonsterInsights is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.1
NVD6.1
|