Sceawere
Vulnerability Detail
CVE-2026-86609UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Download Manager Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- Download Manager
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-27T06:17:14.070Z",
"pubdate": "2026-09-27T06:17:14.070Z",
"executiveSummary": "The Download Manager Pro WordPress plugin, specifically versions prior to 7.5.6, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from the improper sanitization and output escaping of data submitted via the email-locked download subscription form.\nThe vulnerability allows an unauthenticated remote attacker to inject malicious JavaScript payloads into the subscription mechanism. When an administrator accesses the plugin's management interface to review subscription logs or download statistics, the stored malicious script is executed within the context of the administrator's active session.\nSuccessful exploitation poses a critical risk to site integrity and administrative control. By leveraging this vulnerability, an attacker can hijack administrative sessions, exfiltrate sensitive data, or perform unauthorized actions on behalf of the administrator. Because the attack occurs in the administrative backend, it serves as an effective vector for privilege escalation or full site compromise. This issue is isolated to the Pro edition of the plugin; the free version does not contain the affected feature set. Immediate updates to version 7.5.6 or higher are required to mitigate the risk of unauthorized client-side script execution.",
"technicalDetails": "The vulnerability is a classic Stored XSS arising from a failure to perform adequate input validation and output encoding within the email-locked download subscription feature of the Download Manager Pro plugin. The application accepts user-supplied input—specifically email addresses or associated metadata provided during the subscription process—without subjecting the data to rigorous filtering against XSS-prone characters such as <, >, \", and '.\nThe attack flow proceeds as follows: First, an unauthenticated attacker interacts with the email-locked download form. Instead of providing a legitimate email address, the attacker injects a crafted payload containing malicious JavaScript (e.g., <script>alert(document.cookie)</script>) into the input field. The application stores this malicious string in the database as part of the subscriber records. When an administrator subsequently navigates to the plugin's internal dashboard or an administrative reporting page to view the list of subscribers or download activity, the application fetches the stored input and renders it directly into the HTML response stream without applying context-aware output escaping (e.g., htmlspecialchars or wp_kses).\nBecause the payload is rendered directly in the administrator's browser, the injected script executes within the security context of the administrative session. This bypasses typical browser-based security protections and grants the attacker the ability to perform actions within the WordPress dashboard with the permissions of the currently logged-in administrator. The impact is significant: the attacker can force the victim's browser to perform unauthorized administrative tasks, such as creating new rogue user accounts, modifying plugin settings, injecting additional persistent backdoors, or exfiltrating sensitive session tokens, CSRF nonces, and database contents. Since the vulnerability resides within the Pro-only administrative reporting feature, the attack surface is limited to instances where the plugin's premium features are active. No authentication is required to submit the malicious input, and the exploitation is persistent, meaning the payload will trigger every time the affected administrative view is loaded until the record is deleted or the output is properly sanitized by the application."
}