CyberRota Analysis
AI-GeneratedThe Download Monitor plugin for WordPress prior to version 5.2.6 lacks proper authorization checks on a download-logging AJAX action, enabling unauthenticated users to manipulate download logs and artificially inflate download statistics. This vulnerability could lead to misleading analytics and potential reputational damage for affected sites. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.