CVE-2026-4401Disclosure

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is due to missing nonce verification on these functions. This makes it possible for unauthenticated attackers to delete, disable, or enable approved download paths via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-08); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-08: 2Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-20: 1Exploit Tool / Code · 2026-04-20: 1Technical Details · 2026-04-08: 104-0804-20
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-082
Disclosure2
2026-04-201
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4401-download-monitor-version-5-1-10-medium-vulnerability-proof-of-concept CVE-2026-4401 #WordPress plugin #vulnerability download-monitor #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The linked article provides a proof‑of‑concept for CVE‑2026‑4401, targeting the Download Monitor plugin; no evidence of active exploitation or patches is presented.

    0000058
    6 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4401 📊 Severity: 5.4 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4401 #CVE-2026-4401 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/zy9MmDPxr6

    Post summary

    A new CVE (CVE-2026-4401) affecting WordPress was announced with a medium severity score of 5.4, but no further technical, exploitation, or mitigation details were provided.

    0000039
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4401 The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-down… https://www.cve.org/CVERecord?id=CVE-2026-4401

    Post summary

    The post announces a CSRF vulnerability (CVE‑2026‑4401) in the Download Monitor WordPress plugin, detailing the affected methods.

    00000127
    57.0K followersView on X

Explore more