CVE-2026-16608
WordPress Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-16608 is a missing authorization vulnerability (Unauthenticated Download Log Injection) in the Download Monitor WordPress plugin by WP Chill. The plugin fails to perform authorization checks on one of its download-logging AJAX actions and exposes the nonce protecting it to unauthenticated visitors, enabling arbitrary manipulation of download statistics. All versions before 5.2.6 are affected. It carries a CVSS score of 5.3 (Medium) and was publicly disclosed on August 3, 2026, with a patch released in version 5.2.6 (WPScan, GitHub Advisory).

Détails techniques

The root cause is CWE-862 (Missing Authorization), classified under OWASP Top 10 A5: Broken Access Control. The plugin exposes a nonce — normally a CSRF protection token — to unauthenticated visitors, effectively nullifying its protective value. An unauthenticated attacker can then call the unprotected AJAX action with the exposed nonce to inject arbitrary entries into the download log. No authentication or elevated privileges are required for exploitation (WPScan).

Impact

Successful exploitation allows unauthenticated attackers to inject arbitrary download log entries, artificially inflating a site's download statistics. While this does not result in remote code execution, data exfiltration, or direct system compromise, it can corrupt site analytics, mislead administrators about content popularity, and potentially be used to manipulate business decisions or monetization metrics based on download counts (WPScan, GitHub Advisory).

Exploitabilité

No public proof-of-concept (PoC) exploit is currently available; WPScan has indicated the PoC will be published on August 17, 2026, to allow time for users to update. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.00136, reflecting a low probability of near-term exploitation (WPScan, GitHub Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify WordPress sites running the Download Monitor plugin (versions before 5.2.6) using tools like WPScan, Shodan, or by inspecting page source for plugin indicators.
  2. Obtain the exposed nonce: Visit the target site as an unauthenticated user and retrieve the nonce value that the plugin exposes in the page source or via a public endpoint.
  3. Craft the AJAX request: Construct an HTTP POST request targeting the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the appropriate action parameter corresponding to the unprotected download-logging AJAX action, including the obtained nonce.
  4. Inject log entries: Submit the crafted request with arbitrary download log data (e.g., fake download counts, fabricated file references) to inflate the site's download statistics.
  5. Repeat at scale: Automate the request to send large volumes of fake log entries, significantly distorting the site's reported download metrics (WPScan).

Indicateurs de compromis

  • Network: Unusual volume of HTTP POST requests to /wp-admin/admin-ajax.php from unauthenticated (non-logged-in) sources, particularly with action parameters related to Download Monitor logging.
  • Logs: WordPress or web server access logs showing repeated AJAX calls to the download-logging action from diverse or automated IP addresses in a short time window.
  • Application Data: Abnormally high or rapidly increasing download counts in the Download Monitor plugin's statistics dashboard that do not correlate with actual site traffic or user activity.

Atténuation et solutions de contournement

Update the Download Monitor WordPress plugin to version 5.2.6 or later, which restores proper authorization checks on the affected AJAX action. No configuration-based workaround has been published; upgrading is the only recommended remediation. Site administrators should also audit existing download log data for anomalous entries that may have been injected prior to patching (WPScan, GitHub Advisory).

Réactions de la communauté

The vulnerability was discovered and reported by security researcher Anirudh Gupta and verified by WPScan. No significant broader media coverage or notable social media commentary has been identified at this time, consistent with the medium severity rating and limited exploitation impact.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté WordPress Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-16955NONEN/A
  • ai-engine
NonOuiAug 08, 2026
CVE-2026-16953NONEN/A
  • ai-engine
NonOuiAug 08, 2026
CVE-2026-16948NONEN/A
  • solace-extra
NonOuiAug 08, 2026
CVE-2026-16608NONEN/A
  • download-monitor
NonOuiAug 08, 2026
CVE-2026-16595NONEN/A
  • wpdirectorykit
NonOuiAug 08, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités