PT-2026-40465 · WordPress · Monsterinsights

Dmitry Ignatyev

·

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2026-5371

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions MonsterInsights – Google Analytics Dashboard for WordPress versions prior to 10.1.3
Description Missing capability checks in the get ads access token() and reset experience() functions allow authenticated attackers with Subscriber-level access or higher to retrieve live Google OAuth access tokens and reset the Google Ads integration.
Recommendations Update to a version later than 10.1.2. As a temporary workaround, restrict access to the get ads access token() and reset experience() functions to minimize the risk of unauthorized data access and modification.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-5371

Affected Products

Monsterinsights