๐Ÿ” CVE Alert

CVE-2026-14292

UNKNOWN 0.0

WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.

Vendor unknown
Product download manager
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown download manager

Be the first to know when new unknown vulnerabilities affecting unknown download manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Download Manager
0 < 3.3.66

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/719b6675-7891-4742-9751-bba2e72414a8/

Credits

Yaswanth Reddy Sunkara WPScan