CVE-2026-11366

MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass

The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.


We have discovered 558,237 live websites that are affected by CVE-2026-11366.

Run a Free Instant Scan




Affected Software

Product  MonsterInsights
Category Analytics
Vulnerable Domains558,237 live websites (87% of MonsterInsights install base)
Vulnerable Versions
  • from 0 through 11.1
Vulnerable Versions Count188 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Aug 4, 2026
  • Updated - Aug 4, 2026

Credits

  • Đặng Tiến Dũng (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-11366
United States210,101 websites



Japan35,272 websites
Germany32,019 websites
GB29,262 websites
France27,306 websites
Netherlands21,618 websites
Italy17,948 websites
Canada13,930 websites
Spain13,384 websites
Australia12,146 websites

Website Distribution by TLD

Number of websites using CVE-2026-11366
.com270,048 websites
.org32,435 websites
.nl19,140 websites
.co.uk18,252 websites
.net14,719 websites
.de13,237 websites
.it12,614 websites
.fr11,712 websites
.com.au10,635 websites
.pl8,153 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-11366

Top websites that are affected by CVE-2026-11366. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.org United States***
*******.com United States*,***
*********.org United States*,***
************.com United States*,***
**********.com United States*,***
**********.com United States*,***
************.com United States*,***
********.com United States*,***
*********.com United States*,***
*****.com United States*,***
See full domain list

FAQ

CVE-2026-11366 is Improper Authentication in MonsterInsights
A total of 558,237 websites have been identified as vulnerable to CVE-2026-11366, based on global website indexing conducted by WebTechSurvey.
The MonsterInsights is affected by the CVE-2026-11366 vulnerability.
MonsterInsights versions up to 11.1 are vulnerable to CVE-2026-11366.
CVE-2026-11366 is resolved in version 11.1 of MonsterInsights.