Cette page n'a pas encore été traduite dans votre langue. Affichage du contenu en anglais pendant que nous y travaillons.

💡 Keep dependencies up to date — most exploits target known, patchable vulnerabilities.

HIGHCVE-2026-5371CVSS 7.1

CVE-2026-5371: Unauthorized Access in MonsterInsights WordPress Plugin

Plateforme

wordpress

Composant

google-analytics-for-wordpress

Corrigé dans

10.1.3

Traduction vers votre langue…

CVE-2026-5371 is a vulnerability affecting the MonsterInsights WordPress plugin, a popular tool for Google Analytics integration. This flaw allows authenticated attackers, even those with Subscriber-level access, to retrieve live Google OAuth access tokens and manipulate the plugin's Google Ads integration. The vulnerability exists in versions up to 10.1.2 and has been resolved in version 10.1.3, released on May 12, 2026.

WordPress

Détecte cette CVE dans ton projet

Téléverse ton fichier de dépendances et découvre instantanément si cette CVE et d'autres te touchent.

Impact et Scénarios d'Attaquetraduction en cours…

The primary impact of CVE-2026-5371 is the unauthorized access and potential misuse of Google OAuth access tokens. An attacker who exploits this vulnerability could gain access to sensitive data associated with the website's Google Analytics and Google Ads accounts. This could include user data, campaign performance metrics, and potentially even billing information. The ability to reset the Google Ads integration further amplifies the impact, allowing an attacker to disrupt advertising campaigns and potentially redirect funds. While the vulnerability requires authentication, the low access level needed (Subscriber) significantly broadens the attack surface.

Contexte d'Exploitationtraduction en cours…

The vulnerability was published on May 12, 2026. No public exploits or proof-of-concept code have been observed at the time of writing. The CVSS score of 7.1 (HIGH) indicates a significant risk, and the ease of exploitation (requiring only Subscriber-level access) suggests that it could become a target for opportunistic attackers. The vulnerability is not currently listed on KEV or EPSS, but its potential impact warrants close monitoring.

Renseignement sur les Menaces

Statut de l'Exploit

Preuve de ConceptInconnu
CISA KEVNO
Exposition InternetÉlevée
Rapports1 rapport de menace

EPSS

0.03% (percentile 8%)

CISA SSVC

Exploitationnone
Automatisableno
Impact Techniquepartial

Vecteur CVSS

RENSEIGNEMENT SUR LES MENACES· CVSS 3.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N7.1HIGHAttack VectorNetworkComment l'attaquant atteint la cibleAttack ComplexityLowConditions requises pour exploiterPrivileges RequiredLowNiveau d'authentification requisUser InteractionNoneSi une action de la victime est requiseScopeUnchangedImpact au-delà du composant affectéConfidentialityHighRisque d'exposition de données sensiblesIntegrityLowRisque de modification non autorisée de donnéesAvailabilityNoneRisque d'interruption de servicenextguardhq.com · Score de base CVSS v3.1
Que signifient ces métriques?
Attack Vector
Réseau — exploitable à distance via internet. Aucun accès physique ou local requis.
Attack Complexity
Faible — aucune condition spéciale requise. Exploitable de manière fiable.
Privileges Required
Faible — tout compte utilisateur valide est suffisant.
User Interaction
Aucune — attaque automatique et silencieuse. La victime ne fait rien.
Scope
Inchangé — impact limité au composant vulnérable.
Confidentiality
Élevé — perte totale de confidentialité. L'attaquant peut lire toutes les données.
Integrity
Faible — l'attaquant peut modifier certaines données avec un impact limité.
Availability
Aucun — aucun impact sur la disponibilité.

Classification de Faiblesse (CWE)

Chronologie

  1. Réservé
  2. Publiée
  3. Modifiée
  4. EPSS mis à jour

Mitigation et Contournementstraduction en cours…

The primary mitigation for CVE-2026-5371 is to immediately upgrade the MonsterInsights plugin to version 10.1.3 or later. If upgrading is not immediately feasible due to compatibility issues or breaking changes, consider temporarily restricting access to the getadsaccesstoken() and resetexperience() functions. While not a complete fix, this can limit the attacker's ability to exploit the vulnerability. Review WordPress user roles and permissions to ensure that only necessary users have access. Monitor WordPress logs for suspicious activity related to Google OAuth authentication. After upgrading, confirm the fix by attempting to access the Google Ads integration with a Subscriber-level user account and verifying that access is denied.

Comment corriger

Mettre à jour vers la version 10.1.3, ou une version corrigée plus récente

Questions fréquentestraduction en cours…

What is CVE-2026-5371 — Unauthorized Access in MonsterInsights WordPress Plugin?

CVE-2026-5371 is a HIGH severity vulnerability in the MonsterInsights WordPress plugin that allows authenticated subscribers to retrieve Google OAuth tokens and reset Google Ads integration, potentially leading to data exposure and campaign disruption.

Am I affected by CVE-2026-5371 in MonsterInsights WordPress Plugin?

You are affected if you are using the MonsterInsights plugin in WordPress versions 10.1.2 or earlier. Check your plugin version and upgrade immediately if necessary.

How do I fix CVE-2026-5371 in MonsterInsights WordPress Plugin?

Upgrade the MonsterInsights plugin to version 10.1.3 or later. If immediate upgrade is not possible, temporarily restrict access to the vulnerable functions and review user permissions.

Is CVE-2026-5371 being actively exploited?

No public exploits have been observed at this time, but the vulnerability's ease of exploitation and potential impact suggest it could become a target. Continuous monitoring is recommended.

Where can I find the official MonsterInsights advisory for CVE-2026-5371?

Refer to the official MonsterInsights website and WordPress plugin repository for the latest security advisories and updates related to CVE-2026-5371.

Ton projet est-il affecté ?

Téléverse ton fichier de dépendances et découvre instantanément si cette CVE et d'autres te touchent.

WordPress

Détecte cette CVE dans ton projet

Téléverse ton fichier de dépendances et découvre instantanément si cette CVE et d'autres te touchent.

en directfree scan

Scannez votre projet WordPress maintenant — sans compte

scanZone.subtitle

Scan manuelSlack/email alertsContinuous monitoringWhite-label reports

Glissez-déposez votre fichier de dépendances

composer.lock, package-lock.json, requirements.txt, Gemfile.lock, pubspec.lock, Dockerfile...