CVE-2026-3124Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by exploiting a mismatch between the PayPal transaction token and the local order, allowing theft of paid digital goods by paying a minimal amount for a low-cost item and using that payment token to finalize a high-value order.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-30: 3Technical Details · 2026-03-30: 203-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3124 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3124 #CVE-2026-3124 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/kkmQ8cQKt3

    Post summary

    The tweet briefly announces CVE‑2026‑3124 with a 7.5 severity score affecting WordPress, but provides no PoC, exploit details, patch information, or technical specifics.

    0001041
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3124 The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() functio… https://www.cve.org/CVERecord?id=CVE-2026-3124

    Post summary

    The text announces CVE‑2026‑3124, indicating an insecure direct object reference in Download Monitor WordPress plugin up to version 5.1.7.

    0000055
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3124 - Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' Intel Report: https://ift.tt/bKTaBqn

    Post summary

    The alert announces CVE-2026-3124, detailing an Insecure Direct Object Reference vulnerability in Download Monitor <=5.1.7 that allows unauthenticated order completion via token and order_id.

    0000037
    281 followersView on X

Explore more