Junglewise Threat Intelligence

CVE-2026-57427: Download Monitor WPForms Lock unauthenticated XSS

CVE-2026-57427 · Severity: high · CVSS 7.1 · Published 2026-07-23

Executive brief

A vulnerability exists in the Download Monitor - WPForms Lock plugin for WordPress, which is used to restrict file downloads until a user completes a form. An attacker can use this flaw to inject malicious scripts into the website, which are then executed in the browsers of other visitors. This could lead to unauthorized actions, such as redirecting users to malicious sites, stealing session information, or defacing the website's content.

Technical details

The Download Monitor - WPForms Lock plugin for WordPress (versions <= 1.0.4) suffers from an unauthenticated Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link or visiting a malicious page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions if the victim is an administrator. The issue is resolved in version 1.0.5.

Affected products

  • Download Monitor Download Monitor - WPForms Lock <= 1.0.4

Timeline

  • 2026-04-30: other: Reported by researcher dutafi
  • 2026-07-16: disclosed: Initial disclosure by Patchstack
  • 2026-07-23: advisory: CVE published and added to NVD
  • 2026-07-23: patched: Version 1.0.5 released to address the vulnerability

References