Executive brief
The MonsterInsights plugin for WordPress, which connects websites to Google Analytics and Google Ads, contains a security flaw that allows low-level users to access sensitive information. An attacker with a basic account on the site could steal Google OAuth access tokens or disrupt the site's Google Ads integration. This could lead to unauthorized access to advertising data or the disconnection of marketing services.
Technical details
The vulnerability is classified as Missing Authorization (CWE-862) within the get_ads_access_token() and reset_experience() functions of the MonsterInsights plugin. Due to a lack of capability checks, these functions are accessible to any authenticated user, including those with the lowest 'Subscriber' permissions. An attacker can exploit this over the network to retrieve active Google OAuth access tokens or trigger a reset of the Google Ads configuration. The issue affects all versions up to and including 10.1.2; users should update to the latest available version to mitigate the risk.
Affected products
- MonsterInsights MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) Up to, and including, 10.1.2
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
References
- https://plugins.trac.wordpress.org/browser/google-analytics-for-wordpress/tags/10.0.3/includes/admin/admin-assets.php
- https://plugins.trac.wordpress.org/browser/google-analytics-for-wordpress/tags/10.0.3/includes/ppc/google/class-monsterinsights-google-ads.php
- https://plugins.trac.wordpress.org/browser/google-analytics-for-wordpress/tags/10.0.3/includes/ppc/google/class-monsterinsights-google-ads.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5d380b66-675e-451d-a7e3-4efe1fbd08b2?source=cve