Sceawere

Vulnerability Detail

CVE-2026-11976UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MonsterInsights S3 Bucket Supply Chain Compromise

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
1d ago
Vendor
Unknown
Product
MonsterInsights Pro
Attack Type
CWE-912 Hidden Functionality
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-06T22:16:45.103Z",
  "pubdate": "2026-08-06T22:16:45.103Z",
  "executiveSummary": "A supply chain compromise has affected the official MonsterInsights Pro update distribution infrastructure, specifically the Amazon S3 bucket located at monster-insights.s3.amazonaws.com.\nThe vulnerability type is an unauthorized software supply chain modification resulting in the distribution of malicious backdoored releases.\nThe impacted products and versions include MonsterInsights Pro versions 10.2.2 (current release) and 10.2.0 (rolled-back version), both of which contain an unauthorized malicious file named class-system-check.php.\nThe risk implications are severe, as threat actor persistence within the distribution infrastructure allows for remote code execution, unauthorized data access, and potential compromise of all downstream WordPress websites that apply the affected updates.\nThe attacker maintains active write access to the S3 bucket, demonstrating ongoing operational capability and active payload iteration throughout the day.\nExploitation requires administrative or infrastructure-level access to the S3 bucket by the threat actor, while downstream exploitation relies on users downloading and executing the compromised update packages containing the malicious payload.",
  "technicalDetails": "The root cause of the security incident is the unauthorized modification and substitution of legitimate software release artifacts stored within the cloud storage infrastructure controlled by the vendor.\nThe vulnerable component is the update distribution mechanism hosted at monster-insights.s3.amazonaws.com, specifically affecting software distribution packages for MonsterInsights Pro versions 10.2.0 and 10.2.2.\nThe malicious component introduced into the update distribution packages is a file designated as class-system-check.php.\nAnalysis of observed variants indicates the presence of three distinct payload iterations deployed on 2026-06-11, all configured to utilize a shared AES-256-GCM encryption key, confirming attribution to a single unified threat actor.\nThe attack flow begins with unauthorized write access to the cloud storage bucket, enabling the threat actor to inject the malicious class-system-check.php file directly into official update archives.\nDownstream exploitation occurs when site administrators initiate routine updates for MonsterInsights Pro, pulling the compromised packages directly from monster-insights.s3.amazonaws.com over HTTPS.\nUpon installation and execution within the target WordPress environment, the malicious script leverages the shared AES-256-GCM key configuration for encrypted communications, payload decryption, or command execution, facilitating post-exploitation activities.\nNetwork exposure is global via the public S3 bucket endpoint, affecting any deployment retrieving updates during the window of compromise.\nAuthentication and privilege requirements for the initial distribution compromise involve unauthorized write permissions to the S3 bucket, whereas execution on downstream targets occurs with the inherent privileges of the executing web server and WordPress installation."
}
CVE-2026-11976: MonsterInsights S3 Bucket Supply Chain Compromise (CRITICAL Severity, CVSS: 10.0) - Sceawere