What is CVE-2026-11976?
The official MonsterInsights Pro update server (AWS S3 bucket) has been compromised, injecting a malicious `class-system-check.php` file into versions 10.2.2 and 10.2.0. This directly affects all websites using the plugin, requiring immediate disabling or manual cleaning of plugin files.
Azərbaycanca: MonsterInsights Pro plagini üçün rəsmi yeniləmə serveri (AWS S3 bucket) kompromat edilib, nəticədə 10.2.2 və 10.2.0 versiyalarına zərərli `class-system-check.php` faylı əlavə olunub. Bu, plagindən istifadə edən bütün vebsaytları birbaşa təsir edir, ona görə təcili olaraq plagin fayllarının təmizlənməsi və ya deaktivasiyası tövsiyə olunur.
FAQ2
Which versions of the MonsterInsights Pro plugin are affected by the CVE-2026-11976 vulnerability?
This threat specifically affects MonsterInsights Pro plugin versions 10.2.2 and 10.2.0, as the compromised update server injected a malicious `class-system-check.php` file into these versions.
What immediate action is recommended for website owners regarding CVE-2026-11976?
As all websites using the plugin are directly affected, immediate disabling of the plugin or manual cleaning of the plugin files is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.