CVE-2026-11366: MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass
The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MonsterInsights (WordPress plugin)to a version that resolves this vulnerability.Fixed in 11.1.0 - Operational
After upgrading MonsterInsights to 11.1.0, verify the plugin configuration values—unauthenticated attackers could overwrite configuration in Manual GA4 mode due to an empty-key HMAC bypass when the plugin is not connected to Google Analytics.