CVE-2026-11366 PUBLISHED

MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass

Assigner: WPScan
Reserved: 05.06.2026 Published: 04.08.2026 Updated: 04.08.2026

The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.

Product Status

Vendor Unknown
Product MonsterInsights
Versions Default: unaffected
  • affected from 0 to 11.1.0 (excl.)

Credits

  • Đặng Tiến Dũng finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE