← All CVEs NewScan detects
critical

CVE-2026-11976

MonsterInsights Pro 10.2.0 shipped from a compromised update bucket: backdoored class-system-check.php hijacks the MonsterInsights/ExactMetrics update channel to an attacker server, creates a hidden administrator account and adds a GET-parameter authentication bypass

Severity
critical
Affected product
google-analytics-premium
Affected versions
google-analytics-premium ≥ 10.2.0, ≤ 10.2.0
Affected versions
google-analytics-premium ≥ 10.2.2, ≤ 10.2.2
Fixed in
google-analytics-premium 11.0.0
Added to NewScan
2026-08-07
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints google-analytics-premium from its response and reports this CVE when the detected version falls inside the affected range below.

Supply-chain compromise of the vendor's own S3 distribution bucket (monster-insights.s3.amazonaws.com), not a code defect - so the exact-version pin (ge == le) is CORRECT and deliberate, same as the advanced-responsive-video-embedder row: only the two rebuilt artifacts are backdoored and 10.2.1 is clean. A range would false-positive on a clean release. The 10.2.0 variant is the worse of the two: it repoints the update channel at tidio.cc, so the site keeps taking code from the attacker after the plugin is 'updated'. Version source: scan_wordpress mines a version per plugin slug from asset ?ver= and refines it against /wp-content/plugins/<slug>/readme.txt `Stable tag:` - google-analytics-premium is the Pro build's directory slug (the free build is google-analytics-for-wordpress and is NOT affected).

COMPONENT VERSION RANGE

NewScan fingerprints google-analytics-premium from its response and reports this CVE when the detected version falls inside the affected range below.

Second backdoored artifact of the same bucket compromise (CVE-2026-11976) and the one that was the CURRENT release while compromised, so it is the build most installs pulled. Pinned exactly (ge == le) for the same reason as the 10.2.0 row: 10.2.1 is clean and must not be flagged. Two pinned rows rather than one 10.2.0-10.2.2 range is the whole point - coverage bought with a false positive on a clean release does not count.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →