The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by exploiting a mismatch between the PayPal transaction token and the local order, allowing theft of paid digital goods by paying a minimal amount for a low-cost item and using that payment token to finalize a high-value order.
We have discovered 22,271 live websites that are affected by CVE-2026-3124.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 22,271 live websites (63% of Download Monitor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 93 versions ( 95% of all versions) |
| 5,856 websites | |
| 3,848 websites | |
| 1,246 websites | |
| 1,188 websites | |
| 1,093 websites | |
| 862 websites | |
| 761 websites | |
| 685 websites | |
| 513 websites | |
| 440 websites |
| .com | 7,984 websites |
| .de | 2,566 websites |
| .org | 1,638 websites |
| .it | 905 websites |
| .nl | 650 websites |
| .co.uk | 557 websites |
| .net | 555 websites |
| .fr | 490 websites |
| .com.au | 445 websites |
| .pl | 381 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | *,*** | ||
| ***.com | *,*** | ||
| ***********.com | *,*** | ||
| ***************.com | **,*** | ||
| *********.com | **,*** | ||
| ******.gov | **,*** | ||
| ******.com | **,*** | ||
| ***********.com | **,*** | ||
| ***.de | **,*** | ||
| *****.com | **,*** |
FAQ