CVE-2026-86609
Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
| Vendor | unknown |
| Product | download manager |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown download manager
Be the first to know when new unknown vulnerabilities affecting unknown download manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Download Manager
4.0.0 < 7.5.6
References
Credits
Andy WPScan