AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16608

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Download Monitor plugin for WordPress prior to version 5.2.6 lacks proper authorization checks on a download-logging AJAX action, enabling unauthenticated users to manipulate download logs and artificially inflate download statistics. This vulnerability could lead to misleading analytics and potential reputational damage for affected sites. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16608
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.