CVE-2026-14292
Received Received - Intake

Cross-Site Scripting in WordPress Download Manager Plugin

Vulnerability report for CVE-2026-14292, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
download_manager download_manager to 3.3.66 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-Site Scripting (XSS) vulnerability in the Download Manager WordPress plugin before version 3.3.66. It occurs because the plugin fails to properly escape a package's title before displaying it on the front end. This allows users with Author role or higher to inject malicious JavaScript code into the title. When other users view pages containing the affected package, the injected script executes in their browsers.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the Download Manager plugin versions before 3.3.66. Check for packages with malicious JavaScript in titles by reviewing plugin files or using admin access to view package listings. No specific commands are provided in the context.

Impact Analysis

If you are a WordPress site administrator using the Download Manager plugin before 3.3.66, attackers with Author privileges could inject malicious scripts. These scripts could steal user sessions, redirect visitors to phishing sites, or perform actions on behalf of users. Even unauthenticated visitors viewing affected pages could be compromised.

Compliance Impact

This vulnerability could lead to data breaches by allowing attackers to steal user data or session cookies. For GDPR, this may result in unauthorized access to personal data, potentially violating principles of data protection and user consent. For HIPAA, it could expose protected health information if user accounts with access to such data are compromised.

Mitigation Strategies

Update the Download Manager WordPress plugin to version 3.3.66 or later to patch the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14292. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart