CVE-2026-3124

Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id'

The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by exploiting a mismatch between the PayPal transaction token and the local order, allowing theft of paid digital goods by paying a minimal amount for a low-cost item and using that payment token to finalize a high-value order.


We have discovered 22,271 live websites that are affected by CVE-2026-3124.

Run a Free Instant Scan




Affected Software

Product  Download Monitor
Category Wordpress Plugins
Vulnerable Domains22,271 live websites (63% of Download Monitor install base)
Vulnerable Versions
  • from 0 through 5.1.7
Vulnerable Versions Count93 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Mar 30, 2026
  • Updated - Apr 8, 2026

Credits

  • Hung Nguyen (finder)

Website Distribution by Country

Number of websites using CVE-2026-3124
United States5,856 websites



Germany3,848 websites
Italy1,246 websites
France1,188 websites
GB1,093 websites
Japan862 websites
Netherlands761 websites
Spain685 websites
Poland513 websites
Brazil440 websites

Website Distribution by TLD

Number of websites using CVE-2026-3124
.com7,984 websites
.de2,566 websites
.org1,638 websites
.it905 websites
.nl650 websites
.co.uk557 websites
.net555 websites
.fr490 websites
.com.au445 websites
.pl381 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-3124

Top websites that are affected by CVE-2026-3124. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com Singapore*,***
***.com United States*,***
***********.com United States*,***
***************.com United States**,***
*********.com United States**,***
******.gov United States**,***
******.com Japan**,***
***********.com United States**,***
***.de Germany**,***
*****.com United States**,***
See full domain list

FAQ

CVE-2026-3124 is Authorization Bypass Through User-Controlled Key in Download Monitor
A total of 22,271 websites have been identified as vulnerable to CVE-2026-3124, based on global website indexing conducted by WebTechSurvey.
The Download Monitor is affected by the CVE-2026-3124 vulnerability.
Download Monitor versions up to and including 5.1.7 are vulnerable to CVE-2026-3124.