Threats Tagged 'cve-2026-11976'
View all threats tagged with 'cve-2026-11976'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-11976'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-11976: CWE-912 Hidden Functionality in MonsterInsights ProCVE-2026-11976 0 MonsterInsights Pro's official update distribution S3 bucket was compromised, resulting in malicious files being included in versions 10.2.0 and 10.2.2. The malicious file, class-system-check.php, was found in these releases with three variants sharing the same encryption key, indicating a single threat actor with ongoing access. This vulnerability is classified as CWE-912 (Hidden Functionality) and has a critical CVSS score of 10. The attacker retains write access to the update distribution bucket, allowing continuous payload modification. Patch availability is indicated, but specific patch details are not provided. The service is cloud-hosted, so vendor-managed remediation is expected. Join the discussion | CVE Database V5 | 08/07/2026, 00:31:13 UTC Added: 08/06/2026, 22:13:07 UTC |
Showing 1 to 1 of 1 result