CVE Database /
CVE-2026-11366
CVE
CVE-2026-11366 — MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 11.1.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-11366
|
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 11.1.0 |
Improper Authentication |
Unknown
|
< 11.1.0
|
11.1.0 |
2026-08-04 |
—
|
CVE-2026-11366
The MonsterInsights WordPress plugin, prior to version 11.1.0, contains a flaw that allows attackers without authentication to manipulate its configuration settings through an AJAX action. This is possible because the plugin does not properly verify the authenticity of incoming requests when it's disconnected from Google Analytics, allowing malicious actors to forge valid signatures and alter critical settings. As a result, analytics functionality in Manual GA4 mode may be severely impaired.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings