WordPress · Download Monitor · CVE-2026-16608
**Name of the Vulnerable Software and Affected Versions**
Download Monitor versions prior to 5.2.6
**Description**
An issue exists where the plugin fails to perform authorization checks on a download-logging AJAX action. Additionally, the nonce (a unique token used to prevent cross-site request forgery) protecting this action is exposed to unauthenticated visitors. This allows unauthenticated users to inject arbitrary download log entries, which can be used to artificially inflate a site's download statistics.
**Recommendations**
Update Download Monitor to version 5.2.6 or later.