Monsterinsights develops WordPress plugins for analytics integration and user feedback collection, products that sit within the WordPress ecosystem and reach a substantial installed base across web properties. The vendor's disclosures center on cross-site scripting weaknesses that arise from insufficient input neutralization in web-facing plugin interfaces, a pattern consistent with the plugin architecture and server-side templating context. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Monsterinsights over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5902MEDIUM The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in | Jul 12, 2024 | 6.1 | 20 | NO | NO |
CVE-2023-23999MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions. | May 18, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-0903MEDIUM The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_submitted' | Feb 22, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-46153MEDIUM Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.9 versions. | Oct 27, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-23880MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions. | Aug 8, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-32291MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MonsterInsights Pro allows Stored XSS.This issue affects MonsterInsights Pro: | Nov 30, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-39308MEDIUM Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions. | Sep 29, 2023 | 6.1 | 17 | NO | NO |
CVE-2022-3904MEDIUM The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary w | Jan 16, 2023 | 6.1 | 17 | NO | NO |
CVE-2023-0081MEDIUM The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which | Feb 6, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Monsterinsights.
Media articles that mention a CVE ID that affects a product developed by Monsterinsights — matched by CVE ID, not by vendor name.