Sceawere

Vulnerability Detail

CVE-2026-102401UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Download Manager

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
3h ago
Vendor
codename065
Product
Download Manager
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regurl' parameter in all versions up to, and including, 3.3.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload only fires for logged-out site visitors, as the vulnerable login-form.php template branch is gated on !is_user_logged_in(); authenticated users viewing the same page are served a different template and are not affected.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T05:16:38.880Z",
  "pubdate": "2026-10-10T05:16:38.880Z",
  "executiveSummary": "The Download Manager plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper input validation and output encoding.\nThis vulnerability allows authenticated attackers with at least contributor-level access to inject malicious scripts into the 'regurl' parameter, which are subsequently stored in the application database.\nThe malicious payload executes within the context of the victim's browser session when they access the specific page containing the injected content.\nThe exploitation is scoped to unauthenticated users, as the vulnerable template logic within login-form.php only executes when the is_user_logged_in() conditional returns false.\nThe risk implication is significant as it permits the execution of unauthorized scripts, potentially leading to session hijacking, defacement, or redirection to malicious sites.\nSuccessful exploitation requires the attacker to possess authenticated access at the contributor level or higher, necessitating a pre-existing foothold within the WordPress environment.\nAffected versions include all iterations up to and including 3.3.71.",
  "technicalDetails": "The vulnerability resides in the way the Download Manager plugin processes the 'regurl' parameter, specifically within the login-form.php template file.\nThe root cause is a failure to perform adequate input sanitization on the 'regurl' parameter before it is stored, compounded by a lack of appropriate output escaping when the value is rendered back to the browser.\nBecause the input is persisted within the site's database, the XSS is classified as 'Stored' rather than 'Reflected.'\nThe execution flow is gated by a conditional check: the payload is only triggered when the site visitor is not authenticated, as defined by the !is_user_logged_in() function check. Consequently, the payload remains dormant for authenticated users, as the system provides them with a different template branch.\nAn attacker with contributor privileges can perform the following steps: 1) Identify the vulnerable input vector associated with the 'regurl' parameter. 2) Craft a malicious payload, such as <script>alert('XSS')</script> or more sophisticated JavaScript, and inject it via the parameter during a form submission or a specifically crafted request. 3) The plugin processes and saves this unsanitized input to the database. 4) When an unauthenticated visitor requests the specific page rendered by login-form.php, the server fetches the stored payload and embeds it directly into the HTML response. 5) The victim's browser parses the malicious script as legitimate code, resulting in execution.\nThe impact of this execution includes the ability to steal cookies, manipulate the DOM (Document Object Model), perform unauthorized actions on behalf of the victim, or propagate further malicious activity.\nThe technical boundary of this vulnerability is strict, limited by the plugin's template logic which segregates output based on user authentication status. This configuration ensures that while an attacker requires contributor-level access to initiate the stored injection, the payload only impacts external visitors rather than other authenticated site administrators or users.\nThe vulnerable code path involves the interaction between the plugin's data handling methods and the WordPress template engine, where the absence of functions like esc_attr() or esc_html() allows for the rendering of raw, malicious HTML or JavaScript content into the DOM."
}
CVE-2026-102401: Stored XSS in Download Manager (MEDIUM Severity, CVSS: 6.4) | Sceawere