Sceawere

Vulnerability Detail

CVE-2026-9696UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Download Manager Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
3h ago
Vendor
codename065
Product
Download Manager
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'not_found' parameter in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T05:16:40.977Z",
  "pubdate": "2026-10-10T05:16:40.977Z",
  "executiveSummary": "The Download Manager plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 3.3.58.\nThe vulnerability originates from the application's failure to adequately sanitize and escape user-supplied data passed via the 'not_found' parameter.\nSuccessful exploitation allows an authenticated attacker with at least Contributor-level privileges to inject and execute arbitrary JavaScript code within the context of a victim's session.\nWhen a user accesses the page containing the malicious payload, the injected script executes, potentially leading to unauthorized actions, session hijacking, or the theft of sensitive user data.\nThis vulnerability poses a significant security risk, as it allows attackers to compromise the integrity of the affected WordPress site by targeting both administrators and end-users.\nThe attack requires the attacker to hold an authenticated account with sufficient permissions to interact with the vulnerable parameter, though the payload once stored, affects any user who subsequently triggers the rendering of the malicious script.",
  "technicalDetails": "The vulnerability resides within the request handling mechanism of the Download Manager plugin, specifically concerning the processing of the 'not_found' parameter.\nThe root cause is identified as improper neutralization of input during the input handling process, combined with a lack of output encoding/escaping when rendering the data back to the browser.\nIn the affected versions up to 3.3.58, the application accepts input from the 'not_found' parameter and stores it in the database or reflects it directly onto the page without validating the presence of malicious HTML or script tags.\nAn authenticated user with Contributor-level access can supply a crafted payload containing arbitrary web scripts within the 'not_found' parameter field.\nOnce the payload is saved, the application serves this malicious content whenever the associated page is rendered for any user visiting the site.\nThe attack flow follows these steps: first, the authenticated attacker crafts an HTTP request containing a malicious JavaScript payload injected into the 'not_found' parameter. Second, the plugin processes this request and stores the unsanitized input.\nThird, when a target user—which could be a high-privileged administrator—navigates to the manipulated page, the application serves the stored script to the user's browser.\nFinally, the browser interprets the script as legitimate content due to the lack of context-aware output escaping, causing it to execute within the security context of the victim's session.\nThe impact of this exploit is severe, as it grants the attacker the ability to perform actions on behalf of the victim, such as modifying plugin settings, redirecting users, or harvesting session cookies.\nBecause the payload is persistent, the vulnerability remains active until the data is manually removed or the plugin is updated to include proper sanitization and output escaping routines, ensuring that all user-supplied data is treated as untrusted and rendered harmless upon output."
}
CVE-2026-9696: Download Manager Stored XSS (MEDIUM Severity, CVSS: 6.4) | Sceawere