---
id: CVE-2026-16608
title: >-
  The Download Monitor WordPress plugin before 5.2.6 does not perform
  authorization checks on one of its download-logging AJAX actions, and exposes
  the nonce protecting it to unauthenticated visitors, allowing unauthenticated
  users to inje…
summary: >-
  The Download Monitor WordPress plugin before 5.2.6 does not perform
  authorization checks on one of its download-logging AJAX actions, and exposes
  the nonce protecting it to unauthenticated visitors, allowing unauthenticated
  users to inje…
severity: none
published: '2026-08-08'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16608'
references:
  - url: 'https://wpscan.com/vulnerability/f9573555-bd5c-451c-85dd-d964379d12d1/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00304
epssPercentile: 0.20511
ingestedAt: '2026-08-09T03:32:40.593Z'
---

## Overview

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
