CVE-2026-16608: Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16608?
CVE-2026-16608 has a risk rating of 23, indicating a high level of vulnerability.
How do I fix CVE-2026-16608?
To fix CVE-2026-16608, update the Download Monitor plugin to version 5.2.6 or later.
What does CVE-2026-16608 exploit?
CVE-2026-16608 exploits the lack of authorization checks on download-logging AJAX actions in the Download Monitor plugin.
Who is affected by CVE-2026-16608?
Users of the Download Monitor WordPress plugin before version 5.2.6 are affected by CVE-2026-16608.
What type of attack can CVE-2026-16608 facilitate?
CVE-2026-16608 can facilitate unauthenticated log injection attacks, allowing arbitrary download entries.