CVE-2026-3124: Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id'
The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by exploiting a mismatch between the PayPal transaction token and the local order, allowing theft of paid digital goods by paying a minimal amount for a low-cost item and using that payment token to finalize a high-value order.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3124?
CVE-2026-3124 is considered a critical severity vulnerability due to its potential for unauthorized access and exploitation.
How do I fix CVE-2026-3124?
The best way to fix CVE-2026-3124 is to update the Download Monitor plugin to version 5.1.8 or later.
What types of attacks can CVE-2026-3124 facilitate?
CVE-2026-3124 can facilitate unauthorized order completion attacks through insecure direct object references.
Who is affected by CVE-2026-3124?
Any WordPress site using the Download Monitor plugin version 5.1.7 or earlier is affected by CVE-2026-3124.
Is authentication required to exploit CVE-2026-3124?
No, CVE-2026-3124 can be exploited by unauthenticated users, making it particularly dangerous.