{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-07T01:15:36.507","vulnerabilities":[{"cve":{"id":"CVE-2026-11976","sourceIdentifier":"contact@wpscan.com","published":"2026-08-06T22:16:45.103","lastModified":"2026-08-06T22:16:45.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"MonsterInsights Pro","defaultStatus":"unaffected","versions":[{"version":"10.2.0","lessThan":"11.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"contact@wpscan.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}]},"references":[{"url":"https://wpscan.com/vulnerability/d1250410-b919-4a90-8cf2-04031f9e5e2b/","source":"contact@wpscan.com"}]}}]}