The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.
We have discovered 261,434 live websites that are affected by CVE-2026-11976.
| Product | |
| Category | Analytics |
| Vulnerable Domains | 261,434 live websites (41% of MonsterInsights install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 3 versions ( 1.57% of all versions) |
| 108,165 websites | |
| 17,126 websites | |
| 14,845 websites | |
| 14,158 websites | |
| 12,448 websites | |
| 9,818 websites | |
| 7,371 websites | |
| 6,990 websites | |
| 5,236 websites | |
| 5,184 websites |
| .com | 130,449 websites |
| .org | 16,804 websites |
| .co.uk | 9,411 websites |
| .nl | 8,885 websites |
| .net | 7,223 websites |
| .de | 6,140 websites |
| .fr | 5,613 websites |
| .it | 5,235 websites |
| .com.au | 4,610 websites |
| .ca | 4,187 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| *****************.com | *,*** | ||
| ************.com | **,*** | ||
| ****.ca | **,*** | ||
| *********************.fr | **,*** | ||
| ***********.eu | **,*** | ||
| ********.com | **,*** | ||
| *************.com | **,*** | ||
| *******.com | **,*** | ||
| ************.com | **,*** |
FAQ