CVE Database /
CVE-2026-5371
CVE · High
CVE-2026-5371 — MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 10.1.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-5371
|
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 10.1.3 |
Missing Authorization |
High
7.1
|
< 10.1.3
|
10.1.3 |
2026-05-12 |
—
|
CVE-2026-5371
The MonsterInsights plugin for WordPress has a security flaw that allows unauthorized users with at least Subscriber privileges to access sensitive data. Specifically, the get_ads_access_token() and reset_experience() functions lack proper capability checks, enabling attackers to obtain live Google OAuth tokens and reset the plugin's Google Ads settings. This vulnerability affects all versions up to and including 10.1.2.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings