Junglewise Threat Intelligence

CVE-2026-39486: WP Chill Download Monitor SQL injection

CVE-2026-39486 · Severity: high · CVSS 8.5 · Published 2026-04-08

Technologies: WP Chill Download Monitor. Vendors: WP Chill.

Executive brief

WP Chill Download Monitor is a WordPress plugin used to manage and track file downloads on websites. A security vulnerability in versions 5.1.8 and earlier allows an attacker with basic user permissions to perform a 'blind' SQL injection attack. This could lead to the unauthorized extraction of sensitive information from the website's database, potentially compromising user data or site configuration.

Technical details

A Blind SQL Injection vulnerability exists in the WP Chill Download Monitor plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw is present in versions up to and including 5.1.8. An authenticated attacker with at least 'Contributor' level permissions can send specially crafted requests to the server to execute arbitrary SQL queries. Because it is a 'blind' injection, the attacker must infer data based on the application's response or timing rather than seeing the data directly. This can lead to full database disclosure. The issue is resolved in version 5.1.9.

Affected products

  • WP Chill Download Monitor <= 5.1.8

Timeline

  • 2026-02-23: other: Vulnerability reported by researcher daroo
  • 2026-03-25: advisory: Patchstack published advisory and assigned PSID 925def0e9095
  • 2026-04-08: disclosed: CVE-2026-39486 published
  • 2026-05-19: patched: Fixed in version 5.1.9

References

Related threats