PT-2026-28427 · WordPress · Download Monitor
Hung Nguyen
·
Publicado
2026-03-30
·
Atualizado
2026-03-30
·
CVE-2026-3124
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Download Monitor plugin for WordPress versions prior to 5.1.8
Description
The software contains an Insecure Direct Object Reference issue in the
executePayment() function. Missing validation on a user-controlled key allows unauthenticated attackers to complete arbitrary pending orders. This is possible due to a mismatch between the PayPal transaction token and the local order id, potentially enabling theft of paid digital goods by exploiting a payment token from a low-cost item to finalize a high-value order.Recommendations
Update to Download Monitor plugin version 5.1.8 or later.
Correção
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Download Monitor