The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-08 07:17
Updated : 2026-08-26 16:31
NVD link : CVE-2026-16608
Mitre link : CVE-2026-16608
CVE.ORG link : CVE-2026-16608
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
