CVE-2026-16608
Received Received - Intake

Unauthenticated Download Log Injection in Download Monitor WordPress Plugin

Vulnerability report for CVE-2026-16608, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: WPScan

Description

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpdownloadmonitor download_monitor to 5.2.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Download Monitor WordPress plugin before version 5.2.6 allows unauthenticated users to inject fake download log entries. The plugin fails to check user permissions for a specific AJAX action used for logging downloads and exposes the security nonce to visitors without authentication.

Detection Guidance

Check if the Download Monitor WordPress plugin version is below 5.2.6. Inspect network traffic for unauthorized AJAX requests to the vulnerable endpoint. Look for unusual download log entries or spikes in statistics.

Impact Analysis

Attackers can manipulate download statistics by injecting arbitrary log entries, making it appear as though downloads occurred when they did not. This could distort analytics, mislead users about content popularity, or be used to artificially inflate metrics for competitive or fraudulent purposes.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves manipulation of download statistics rather than unauthorized access to sensitive data. However, inflated download metrics could lead to inaccurate reporting, which may indirectly impact compliance if metrics are used for audits or regulatory filings.

Mitigation Strategies

Update the Download Monitor plugin to version 5.2.6 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16608. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart