NONE · 0

CVE-2026-16608

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, a...

Vulnerability Description

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.

References

FAQ

What is CVE-2026-16608?

CVE-2026-16608 is a documented vulnerability. The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, a...

How severe is CVE-2026-16608?

CVSS scoring is not yet available for CVE-2026-16608. Check NVD for updates.

Is there a patch for CVE-2026-16608?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.