CVE-2026-16608 - Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
CVE ID :CVE-2026-16608
Published : Aug. 8, 2026, 6 a.m. | 1 hour, 27 minutes ago
Description :The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 8, 2026, 6 a.m. | 1 hour, 27 minutes ago
Description :The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...