CVE · High

CVE-2026-5371 — MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 10.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5371 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 10.1.3 Missing Authorization High 7.1 < 10.1.3 10.1.3 2026-05-12

CVE-2026-5371

The MonsterInsights plugin for WordPress has a security flaw that allows unauthorized users with at least Subscriber privileges to access sensitive data. Specifically, the get_ads_access_token() and reset_experience() functions lack proper capability checks, enabling attackers to obtain live Google OAuth tokens and reset the plugin's Google Ads settings. This vulnerability affects all versions up to and including 10.1.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.