A critical vulnerability (CVE-2026-11976) involves the compromise of the official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`). Both the current release (10.2.2) and a rolled-back version (10.2.0) contain a malicious `class-system-check.php` file. Analysis of three observed variants on 2026-06-11 revealed identical AES-256-GCM encryption keys, confirming a single threat actor. The attacker retains write access to the S3 bucket and continues modifying payloads. This affects WordPress sites using MonsterInsights Pro via Amazon S3. The CVSS 10.0 score reflects the severity of remote code execution risks. Immediate actions include verifying file integrity, blocking access to the compromised S3 bucket, and monitoring for official security updates from the vendor.
CRITICAL
CVSS 10.0
CVE-2026-11976
2026-08-16
Critical Compromise in MonsterInsights Pro S3 Bucket (CVE-2026-11976)
The official MonsterInsights Pro S3 update bucket was compromised, distributing malicious code in versions 10.2.2 and 10.2.0. Attackers maintain access and actively update payloads. Immediate mitigation required.