目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-11366— MonsterInsights < 11.1.0 未认证HMAC绕过秘密更新漏洞

AI Predicted 5.3 Difficulty: Easy
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-11366の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass
ソース: CVE Program / CVE List V5
脆弱性説明
The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
UnknownMonsterInsights 0 ~ 11.1.0 -

II. CVE-2026-11366の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-11366のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-11366 其他参考 (1)

Same Patch Batch · Unknown · 2026-08-04 · 24 CVEs total

CVE-2026-16056Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_op
CVE-2026-16618ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execut
CVE-2026-10526EmbedPress < 4.6.1 - Unauthenticated Blind SSRF
CVE-2026-16536Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_i
CVE-2026-16623Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)
CVE-2026-12698wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile
CVE-2026-14939Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery v
CVE-2026-14816The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Reques
CVE-2026-14872Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injectio
CVE-2026-14824Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question
CVE-2026-14848Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process
CVE-2026-16035miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send
CVE-2026-16296Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler
CVE-2026-15233Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title
CVE-2026-15958Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access
CVE-2026-16293Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL
CVE-2026-16068Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Co
CVE-2026-16069Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point
CVE-2026-16070Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR
CVE-2026-16548Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint

Showing 20 of 24 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-11366へのコメント

まだコメントはありません


コメントを残す