Sceawere
Vulnerability Detail
CVE-2026-12054UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Download Manager Reflected XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 2h ago
- Vendor
- codename065
- Product
- Download Manager
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-10T06:16:41.287Z",
"pubdate": "2026-10-10T06:16:41.287Z",
"executiveSummary": "The Download Manager plugin for WordPress is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability due to improper handling of user-supplied data. The vulnerability resides in the processing of the 'REFERRER' parameter.\nUnauthenticated attackers can exploit this flaw by crafting malicious URLs containing arbitrary JavaScript payloads. When a victim interacts with the compromised link, the payload is reflected in the application's response, executing within the context of the victim's browser session.\nSuccessful exploitation allows attackers to execute unauthorized scripts, potentially leading to session hijacking, credential theft, sensitive information exposure, or unauthorized actions performed on behalf of the authenticated user. This vulnerability affects all versions of the Download Manager plugin up to and including 3.3.57.\nGiven that the exploit does not require authentication or elevated privileges, the risk profile is significant. Organizations should prioritize updating the plugin or implementing strict input filtering to mitigate the risk of exploitation.",
"technicalDetails": "The vulnerability is identified as a Reflected Cross-Site Scripting (XSS) flaw, stemming from the application's failure to sanitize the 'REFERRER' parameter before reflecting it back to the user's browser. The application component responsible for handling download tracking or redirection logic incorrectly trusts the incoming HTTP Referer or a similarly named request parameter.\nThe root cause is an inadequate implementation of output encoding and input validation mechanisms. By injecting malicious script tags (e.g., <script>alert(document.cookie)</script>) into the 'REFERRER' parameter, an attacker forces the server to include this raw, unsanitized input in the resulting HTML response. Because the application fails to utilize context-aware output escaping, the browser interprets the injected string as executable code rather than plain text.\nThe attack flow follows a typical reflected XSS pattern: 1) The attacker constructs a malicious URL incorporating a JavaScript payload within the 'REFERRER' parameter. 2) The attacker distributes this URL to a targeted user via social engineering, phishing, or by embedding it on a malicious site. 3) The target user clicks the link, initiating an HTTP request to the vulnerable WordPress site. 4) The server processes the request, includes the malicious payload in the dynamically generated page, and sends the response back to the victim. 5) The victim's browser parses the malicious response, executing the script in the security context of the target domain.\nThis vulnerability is particularly dangerous because it bypasses standard security measures by utilizing a legitimate application component to deliver the payload. As the exploit is reflected, no persistent storage of the payload is required on the server-side, complicating traditional detection methods that focus on database inspection. The post-exploitation impact allows for the theft of session tokens (e.g., WordPress authentication cookies), which can be used to escalate privileges, modify site content, or gain administrative control over the WordPress installation. Furthermore, the payload can be utilized to perform cross-site request forgery (CSRF) or redirect the victim to malicious domains for further exploitation."
}