
PEACH
Un cadre d’isolation des locataires
CVE-2026-16608 is a missing authorization vulnerability (Unauthenticated Download Log Injection) in the Download Monitor WordPress plugin by WP Chill. The plugin fails to perform authorization checks on one of its download-logging AJAX actions and exposes the nonce protecting it to unauthenticated visitors, enabling arbitrary manipulation of download statistics. All versions before 5.2.6 are affected. It carries a CVSS score of 5.3 (Medium) and was publicly disclosed on August 3, 2026, with a patch released in version 5.2.6 (WPScan, GitHub Advisory).
The root cause is CWE-862 (Missing Authorization), classified under OWASP Top 10 A5: Broken Access Control. The plugin exposes a nonce — normally a CSRF protection token — to unauthenticated visitors, effectively nullifying its protective value. An unauthenticated attacker can then call the unprotected AJAX action with the exposed nonce to inject arbitrary entries into the download log. No authentication or elevated privileges are required for exploitation (WPScan).
Successful exploitation allows unauthenticated attackers to inject arbitrary download log entries, artificially inflating a site's download statistics. While this does not result in remote code execution, data exfiltration, or direct system compromise, it can corrupt site analytics, mislead administrators about content popularity, and potentially be used to manipulate business decisions or monetization metrics based on download counts (WPScan, GitHub Advisory).
No public proof-of-concept (PoC) exploit is currently available; WPScan has indicated the PoC will be published on August 17, 2026, to allow time for users to update. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.00136, reflecting a low probability of near-term exploitation (WPScan, GitHub Advisory).
/wp-admin/admin-ajax.php) with the appropriate action parameter corresponding to the unprotected download-logging AJAX action, including the obtained nonce./wp-admin/admin-ajax.php from unauthenticated (non-logged-in) sources, particularly with action parameters related to Download Monitor logging.Update the Download Monitor WordPress plugin to version 5.2.6 or later, which restores proper authorization checks on the affected AJAX action. No configuration-based workaround has been published; upgrading is the only recommended remediation. Site administrators should also audit existing download log data for anomalous entries that may have been injected prior to patching (WPScan, GitHub Advisory).
The vulnerability was discovered and reported by security researcher Anirudh Gupta and verified by WPScan. No significant broader media coverage or notable social media commentary has been identified at this time, consistent with the medium severity rating and limited exploitation impact.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."