Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-11976Compromiso de cadena de suministro en MonsterInsights Pro

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.

Ver en NVD

Análisis

El bucket oficial de MonsterInsights Pro fue comprometido para distribuir versiones maliciosas del plugin de WordPress que contienen puertas traseras. El atacante mantiene acceso de escritura e inyectó código para ejecución remota en las versiones 10.2.2 y 10.2.0. Si utilizas esta herramienta, revisa inmediatamente tus servidores en busca del archivo malicioso class-system-check.php.

Roles relevantes

PhpCyberSecurityCloudBackend

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.

Publicada: 6/8/2026, 22:16:45
Última modificación: 6/8/2026, 22:16:45

Referencias

InicioEventosBlogRecursosCursosEquipo