Sceawere

Vulnerability Detail

CVE-2026-100182UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Download Monitor Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
15h ago
Vendor
wpchill
Product
Download Monitor
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to trick an authenticated Administrator into visiting an attacker-controlled page that targets an open Download edit screen, after which the payload is persisted unfiltered via the Administrator's unfiltered_html capability and later emitted verbatim to the frontend by the [download_data] shortcode's unescaped post_content render path.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T08:16:59.697Z",
  "pubdate": "2026-10-02T08:16:59.697Z",
  "executiveSummary": "The Download Monitor plugin for WordPress, in versions up to and including 5.2.10, contains a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability arises from insufficient input sanitization and output escaping within the plugin's administrative interface and shortcode rendering processes.\nThe vulnerability allows an unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session. By tricking an authenticated administrator into visiting a malicious third-party site, an attacker can leverage Cross-Origin postMessage communication to interact with an open Download edit screen. This interaction results in the injection of malicious scripts into the plugin's content fields.\nBecause the administrator holds the unfiltered_html capability, these payloads are persisted within the database without validation. Subsequently, when the [download_data] shortcode is utilized, the stored payload is emitted verbatim to the frontend, leading to XSS execution whenever a user views the affected page.\nThe primary risk implications include unauthorized access to administrative sessions, potential account takeover, and the execution of arbitrary actions on behalf of site administrators. Successful exploitation requires social engineering against an authenticated administrator and the presence of an active, open administrative session targeting the Download edit screen.",
  "technicalDetails": "The vulnerability originates from a failure to adequately sanitize and escape input handled via the plugin's administrative editor. The specific attack vector leverages a Cross-Origin postMessage interface, which allows external scripts to interact with the Download edit screen if an administrator currently has that page active in their browser.\nThe exploit flow follows a structured path: First, an attacker crafts a malicious external webpage containing JavaScript designed to dispatch a postMessage event to the WordPress administrative dashboard. Second, the attacker induces an authenticated administrator to navigate to this malicious page. Third, upon receiving the postMessage, the Download Monitor plugin's administrative script processes the incoming data and updates the Download post content with the attacker's payload.\nBecause the WordPress administrator possesses the unfiltered_html capability—a standard privilege for users with the 'Administrator' role—the plugin fails to scrub or sanitize the malicious input. The payload is subsequently saved directly to the database as part of the post_content. This bypasses typical WordPress security filters that would otherwise restrict script tags or other executable HTML elements.\nThe persistence of the XSS payload is achieved because the [download_data] shortcode, which is responsible for rendering content associated with Download objects, does not perform output escaping. When the shortcode is processed, the backend retrieves the tainted post_content from the database and renders it directly into the HTML source of the frontend response.\nAffected versions are Download Monitor up to and including 5.2.10. The vulnerability is categorized as Stored XSS due to the permanent nature of the injection. The impact is significant, as it facilitates the hijacking of administrative sessions, the redirection of users to malicious domains, or the silent exfiltration of sensitive site data through client-side manipulation. The requirement for an active administrative session necessitates a degree of social engineering, but once the payload is injected, it resides within the database, ensuring that any user, including guests or other administrators, who views the affected download component will trigger the malicious script in their browser environment."
}
CVE-2026-100182: Download Monitor Stored XSS (HIGH Severity, CVSS: 7.2) | Sceawere