CVE-2026-14292
WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.
| Vendor | unknown |
| Product | download manager |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown download manager
Be the first to know when new unknown vulnerabilities affecting unknown download manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Download Manager
0 < 3.3.66
References
Credits
Yaswanth Reddy Sunkara WPScan