WordPress Plugin Vulnerabilities

Download Monitor < 5.2.6 - Unauthenticated Download Log Injection

Description

The plugin does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.

Proof of Concept

Affects Plugins

Fixed in 5.2.6

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Anirudh Gupta
Submitter
Anirudh Gupta
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 26 days ago)
Added
2026-08-03 (about 25 days ago)
Last Updated
2026-08-03 (about 25 days ago)

Other