CVE-2026-16608 PUBLISHED

Download Monitor < 5.2.6 - Unauthenticated Download Log Injection

Assigner: WPScan
Reserved: 22.07.2026 Published: 08.08.2026 Updated: 08.08.2026

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.

Product Status

Vendor Unknown
Product Download Monitor
Versions Default: unaffected
  • affected from 0 to 5.2.6 (excl.)

Credits

  • Anirudh Gupta finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE