CVE-2026-16608
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-16608 is a missing authorization vulnerability (Unauthenticated Download Log Injection) in the Download Monitor WordPress plugin by WP Chill. The plugin fails to perform authorization checks on one of its download-logging AJAX actions and exposes the nonce protecting it to unauthenticated visitors, enabling arbitrary manipulation of download statistics. All versions before 5.2.6 are affected. It carries a CVSS score of 5.3 (Medium) and was publicly disclosed on August 3, 2026, with a patch released in version 5.2.6 (WPScan, GitHub Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization), classified under OWASP Top 10 A5: Broken Access Control. The plugin exposes a nonce — normally a CSRF protection token — to unauthenticated visitors, effectively nullifying its protective value. An unauthenticated attacker can then call the unprotected AJAX action with the exposed nonce to inject arbitrary entries into the download log. No authentication or elevated privileges are required for exploitation (WPScan).

Impact

Successful exploitation allows unauthenticated attackers to inject arbitrary download log entries, artificially inflating a site's download statistics. While this does not result in remote code execution, data exfiltration, or direct system compromise, it can corrupt site analytics, mislead administrators about content popularity, and potentially be used to manipulate business decisions or monetization metrics based on download counts (WPScan, GitHub Advisory).

Exploitability

No public proof-of-concept (PoC) exploit is currently available; WPScan has indicated the PoC will be published on August 17, 2026, to allow time for users to update. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.00136, reflecting a low probability of near-term exploitation (WPScan, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Download Monitor plugin (versions before 5.2.6) using tools like WPScan, Shodan, or by inspecting page source for plugin indicators.
  2. Obtain the exposed nonce: Visit the target site as an unauthenticated user and retrieve the nonce value that the plugin exposes in the page source or via a public endpoint.
  3. Craft the AJAX request: Construct an HTTP POST request targeting the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the appropriate action parameter corresponding to the unprotected download-logging AJAX action, including the obtained nonce.
  4. Inject log entries: Submit the crafted request with arbitrary download log data (e.g., fake download counts, fabricated file references) to inflate the site's download statistics.
  5. Repeat at scale: Automate the request to send large volumes of fake log entries, significantly distorting the site's reported download metrics (WPScan).

Indicators of compromise

  • Network: Unusual volume of HTTP POST requests to /wp-admin/admin-ajax.php from unauthenticated (non-logged-in) sources, particularly with action parameters related to Download Monitor logging.
  • Logs: WordPress or web server access logs showing repeated AJAX calls to the download-logging action from diverse or automated IP addresses in a short time window.
  • Application Data: Abnormally high or rapidly increasing download counts in the Download Monitor plugin's statistics dashboard that do not correlate with actual site traffic or user activity.

Mitigation and workarounds

Update the Download Monitor WordPress plugin to version 5.2.6 or later, which restores proper authorization checks on the affected AJAX action. No configuration-based workaround has been published; upgrading is the only recommended remediation. Site administrators should also audit existing download log data for anomalous entries that may have been injected prior to patching (WPScan, GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by security researcher Anirudh Gupta and verified by WPScan. No significant broader media coverage or notable social media commentary has been identified at this time, consistent with the medium severity rating and limited exploitation impact.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16955NONEN/A
  • ai-engine
NoYesAug 08, 2026
CVE-2026-16953NONEN/A
  • ai-engine
NoYesAug 08, 2026
CVE-2026-16948NONEN/A
  • solace-extra
NoYesAug 08, 2026
CVE-2026-16608NONEN/A
  • download-monitor
NoYesAug 08, 2026
CVE-2026-16595NONEN/A
  • wpdirectorykit
NoYesAug 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management