What is CVE-2026-16608?
CVE-2026-16608 is a vulnerability in the Download Monitor WordPress plugin before version 5.2.6, where missing authorization checks and exposed nonce on a download-logging AJAX action allow unauthenticated users to inject arbitrary download log entries. This can be exploited to artificially inflate a site's download statistics. Immediate update to version 5.2.6 or later is required.
Azərbaycanca: CVE-2026-16608, Download Monitor WordPress pluqininin 5.2.6-dan əvvəlki versiyalarında müəyyən bir AJAX əməliyyatı üzərində avtorizasiya yoxlamasının aparılmaması və qoruyucu nonce-in autentifikasiya olunmamış istifadəçilərə ifşa edilməsi səbəbindən yaranan zəiflikdir. Bu, autentifikasiya olunmamış hücumçulara saytın endirmə statistikasını manipulyasiya etmək üçün ixtiyari endirmə log qeydləri yeritməyə imkan verir. Pluqini dərhal 5.2.6 versiyasına və ya daha yuxarısına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-16608?
This vulnerability affects the Download Monitor plugin in versions prior to 5.2.6.
What can an unauthenticated attacker do by exploiting this vulnerability?
An attacker can inject arbitrary download log entries to manipulate the site's download statistics.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.