CVE

CVE-2026-11366 — MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 11.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-11366 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 11.1.0 Improper Authentication Unknown < 11.1.0 11.1.0 2026-08-04

CVE-2026-11366

The MonsterInsights WordPress plugin, prior to version 11.1.0, contains a flaw that allows attackers without authentication to manipulate its configuration settings through an AJAX action. This is possible because the plugin does not properly verify the authenticity of incoming requests when it's disconnected from Google Analytics, allowing malicious actors to forge valid signatures and alter critical settings. As a result, analytics functionality in Manual GA4 mode may be severely impaired.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.