What is CVE-2026-57427?
An Unauthenticated Cross Site Scripting (XSS) vulnerability has been discovered in the "Download Monitor - WPForms Lock" plugin, affecting versions <= 1.0.4. This flaw allows attackers to execute malicious scripts on affected sites without authentication. The plugin must be updated to the latest version immediately.
Azərbaycanca: Doğrulanmamış İstifadəçi tərəfindən Saytlararası Skript (XSS) zəifliyi "Download Monitor - WPForms Lock" plaginində, 1.0.4 və daha əvvəlki versiyalarda aşkarlanıb. Bu boşluq təcavüzkarlara heç bir autentifikasiya olmadan təsirlənmiş saytlarda zərərli skriptlər işlətməyə imkan verir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Does the CVE-2026-57427 vulnerability in the 'Download Monitor - WPForms Lock' plugin require authentication?
No, CVE-2026-57427 is classified as an Unauthenticated Cross Site Scripting (XSS) vulnerability, meaning the attacker does not need to log in to the site to exploit it.
Which versions of the 'Download Monitor - WPForms Lock' plugin are affected by CVE-2026-57427?
This vulnerability affects plugin versions 1.0.4 and earlier (<= 1.0.4).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.