The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
CVE-2026-16608
NONE
EPSS 0.14%
Updated Aug 08, 2026
Unknown
unknown:download monitor
CVE Details
CVE ID
CVE-2026-16608
Published Date
Aug 08, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.14%
Likelihood of exploitation in next 30 days
Percentile:
3.5th percentile (higher than 3.5% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory