Sceawere

Vulnerability Detail

CVE-2026-97338UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Download Manager

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
15h ago
Vendor
codename065
Product
Download Manager
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the [wpdm_edit_profile] shortcode to be present on a front-end page accessible to Subscriber-level users, who can then submit a multiply entity-encoded payload via the display name field to bypass sanitization.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-02T08:17:05.150Z",
  "pubdate": "2026-10-02T08:17:05.150Z",
  "executiveSummary": "The Download Manager plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability residing within its profile management functionality. Affecting all versions up to and including 3.3.70, this security flaw stems from inadequate input validation and output sanitization protocols.\nThe vulnerability allows authenticated users with at least Subscriber-level privileges to inject malicious JavaScript into the application's database. By leveraging the [wpdm_edit_profile] shortcode, an attacker can input specially crafted payloads into the 'Display Name' field. These payloads bypass existing sanitization mechanisms through multiple entity encoding.\nOnce the malicious script is stored, it executes within the context of any user session that accesses the compromised page, including administrators. This creates significant security risks, as the injected scripts can be utilized to steal sensitive session cookies, perform unauthorized actions on behalf of the victim, or redirect users to malicious domains. The impact is severe, potentially leading to full account takeover or administrative compromise depending on the target session's privileges. Because this is a stored XSS, the payload remains persistent until manually purged from the database, posing a continuous threat to any user interacting with the affected content.",
  "technicalDetails": "The root cause of this vulnerability is a failure in the input validation layer of the Download Manager plugin, specifically within the user profile update process. The application fails to properly sanitize the 'Display Name' field before committing it to the database, and conversely, fails to adequately escape this data during output rendering on the front-end.\nThe vulnerability is accessible via the [wpdm_edit_profile] shortcode. When this shortcode is rendered on a front-end page, it exposes an interface for authenticated users to update their profile information. An attacker with Subscriber-level privileges can interact with this interface to submit a malicious payload. The sanitization logic is deficient because it does not account for multiply entity-encoded inputs, allowing malicious scripts to bypass security filters that might otherwise detect standard character sequences like <script>.\nThe exploitation flow is as follows: 1) The attacker navigates to the front-end page where [wpdm_edit_profile] is implemented. 2) The attacker identifies the 'Display Name' field as a vector for input. 3) The attacker crafts a payload utilizing multiple HTML entity encoding (e.g., nesting &lt; and &amp; entities) to obfuscate the script tag. 4) The application receives the encoded input, fails to decode and sanitize it, and stores the malicious string directly into the database. 5) When an unsuspecting user, such as an administrator, visits a page displaying the attacker's profile information, the browser interprets the stored, decoded string as executable JavaScript.\nBecause the script executes in the user's browser, it operates within the security context of the victim's session. This enables the execution of arbitrary commands using the victim's authentication tokens. The impact includes, but is not limited to, session hijacking, persistent defacement, or the automated creation of rogue administrative accounts if the victim is an administrator. The exposure is high, as it requires only basic user access and an enabled profile editing shortcode, which is a common configuration in many WordPress environments utilizing membership or download management features. The vulnerability persists across all plugin versions up to and including 3.3.70, representing a widespread security deficiency for users relying on this specific component."
}
CVE-2026-97338: Stored XSS in Download Manager (MEDIUM Severity, CVSS: 6.4) | Sceawere