CVE-2026-11976
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
The official MonsterInsights Pro update distribution bucket (monster-insights.s3.amazonaws.com) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, class-system-check.php. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | MonsterInsights Pro | 10.2.0 < 11.0.0 | affected |
Weaknesses
- CWE-912 Hidden Functionality
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.