CVE-2026-86610
Received Received - Intake

Stored XSS in Download Manager WordPress Plugin

Vulnerability report for CVE-2026-86610, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: WPScan

Description

The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue, including administrators. Only sites running PHP below 8.1 are affected, as the sanitisation applied when the setting is saved does not neutralise single quotes there.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpdownloadmanager download_manager to 3.3.71 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Stored Cross-Site Scripting (XSS) vulnerability in the Download Manager WordPress plugin versions before 3.3.71. Users with Author role or higher can inject malicious scripts into package settings. These scripts execute when other users, including administrators, open the package's download dialogue. The issue occurs because the plugin does not properly sanitize and escape package settings before displaying them.

Detection Guidance

Check if the Download Manager WordPress plugin version is below 3.3.71 by inspecting the plugin files or WordPress admin panel. Look for stored XSS payloads in package settings, particularly in the package icon field. Review server logs for unusual script execution during download dialogues.

Impact Analysis

Attackers could steal sensitive user data like cookies or session tokens, perform actions on behalf of users, or take control of the affected WordPress site. Administrators visiting a compromised package could have their accounts hijacked. The impact is limited to sites running PHP versions below 8.1 due to sanitization differences.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection requirements. For HIPAA, it may compromise protected health information if exploited on healthcare-related sites. Organizations must patch quickly to maintain compliance with these regulations.

Mitigation Strategies

Update the Download Manager plugin to version 3.3.71 or later immediately. If updating is not possible, disable the plugin temporarily until a patch is applied. Restrict Author role permissions to reduce exposure to potential exploits.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86610. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart