CVE-2026-16608

NONE EPSS 0.14%
Updated Aug 08, 2026
Unknown
Parameter Value
Affected Versions before 5.2.6
Type CWE-862 Missing Authorization
Vendor Unknown
Public PoC No

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.

Vulnerable Products

unknown:download monitor