CVE-2026-11976Disclosure

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-912

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-07); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-07: 3Mentions · 2026-08-10: 1PoC Mentioned / Linked · 2026-08-07: 1Active Exploitation · 2026-08-07: 1Technical Details · 2026-08-07: 2Technical Details · 2026-08-10: 108-0708-10
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-073
Active Exploitation1Disclosure1General1
2026-08-101
Disclosure1
Full discourse4 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-11976 CVE-2026-14812 CVE-2026-5430 CVE-2026-65553 CVE-2026-66665 ..🧵👇

    Post summary

    The content merely lists CVID identifiers without any further context or actionable information.

    1001054
    29 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    [CVE] CVE-2026-11976 [HIGH PRIORITY] #MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise 🔗 https://exploitgrid.net/cve/CVE-2026-11976

    Post summary

    The announcement reveals a new CVE involving a MonsterInsights Pro backdoor introduced through an AWS S3 bucket, with a link likely providing PoC details, but no exploitation evidence or patch information is given.

    1000044
    29 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🪣 MonsterInsights Pro backdoored via compromised AWS S3 bucket. Versions 10.2.0 & 10.2.2 both poisoned — the rollback wasn't safe either. CVE-2026-11976, CVSS 10. If it auto-updated, assume compromise. #cybersecurity #ciso #wordpress #msp #mssp https://secalerts.co/vulnerability/CVE-2026-11976?utm_campaign=x https://t.co/JMzs3rSCcW

    Post summary

    The tweet announces that MonsterInsights Pro versions 10.2.0 and 10.2.2 are backdoored via a compromised AWS S3 bucket, introduces CVE-2026-11976 with a CVSS score of 10, and cautions that auto‑updates may expose systems to compromise.

    00000253
    876 followersView on X
  • Upwind Security MDR@UpwindMDR
    Active Exploitation

    🚨Critical - MonsterInsights Pro Supply-Chain Backdoor via Compromised Update S3 Bucket (CVE-2026-11976) MonsterInsights Pro update artifacts from the official S3 distribution bucket were tampered to include a malicious class-system-check.php; upgrading or rolling back to 10.2.2/10.2.0 pulls the backdoored file. Multiple payload variants (same AES-256-GCM key) observed 2026-06-11; attacker reportedly retained bucket write access. 👉Affected: MonsterInsights Pro 10.2.0 and 10.2.2

    Post summary

    The post details how MonsterInsights Pro’s update distribution bucket was compromised to deploy a backdoor, noting multiple payload variants and ongoing bucket access, with no patch or exploit code disclosed.

    00000107
    282 followersView on X

Explore more