CVE-2026-16608: Unknown Download Monitor

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.

Affected products

  • Unknown Download Monitor: before 5.2.6 (fixed in 5.2.6)

Published 2026-08-08. Last modified 2026-08-26.