CVE-2026-11976: MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
The official MonsterInsights Pro update distribution bucket (monster-insights.s3.amazonaws.com) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, class-system-check.php. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
MonsterInsights Pro (malicious file: class-system-check.php)from your environment.Remove the backdoored file `class-system-check.php` from your MonsterInsights Pro installation(s).
- Operational
Given the attacker retained write access to the compromised update distribution S3 bucket and iterated the payload, assume the malicious payload may have been reintroduced by subsequent installs/updates; re-verify the presence and integrity of `class-system-check.php` after any remediation and do not rely on prior cached versions.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11976?
The severity of CVE-2026-11976 is rated as critical with a score of 10.
How do I fix CVE-2026-11976?
To fix CVE-2026-11976, you should immediately remove affected versions 10.2.0 and 10.2.2 of MonsterInsights Pro and install a secure update.
What versions of MonsterInsights Pro are affected by CVE-2026-11976?
CVE-2026-11976 affects both versions 10.2.0 and 10.2.2 of MonsterInsights Pro.
What is the impact of CVE-2026-11976?
CVE-2026-11976 allows for remote code execution due to a backdoor embedded in the compromised files.
How did the compromise occur in CVE-2026-11976?
The compromise in CVE-2026-11976 occurred through a security breach of the AWS S3 bucket used for official updates.