CVE-2026-5371Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all versions up to, and including, 10.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve live Google OAuth access tokens and reset Plugins's Google Ads integration.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-13)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-12: 1Mentions · 2026-05-13: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 205-1205-13
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-132
Disclosure1General1
Full discourse3 posts
  • Kaitan ID Security@KaitanSecurity
    General

    ⚠️ HIGH — CVE-2026-5371 The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulner… CVSS 7.1 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5371 #Google #CyberSecurity #InfoSec

    Post summary

    The post announces CVE-2026-5371 affecting the MonsterInsights WordPress plugin with a CVSS of 7.1, but offers no PoC, exploit, or patch details, merely a link to an external analysis.

    0000060
    90 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5371 Unauthorized Data Access and Modification in MonsterInsights Plugi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5371 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    Alert for CVE‑2026‑5371, describing a vulnerability that permits unauthorized data access and modification in the MonsterInsights plugin.

    0000047
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5371 The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of d… https://www.cve.org/CVERecord?id=CVE-2026-5371

    Post summary

    The snippet announces CVE‑2026‑5371 affecting the MonsterInsights WordPress plugin, noting an unauthorized access and data modification flaw, but provides no PoC, exploit, or patch details.

    00000105
    57.5K followersView on X

Explore more