CVE-2026-16608

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-08 07:17

Updated : 2026-08-26 16:31


NVD link : CVE-2026-16608

Mitre link : CVE-2026-16608

CVE.ORG link : CVE-2026-16608


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization