๐Ÿ” CVE Alert

CVE-2026-86609

UNKNOWN 0.0

Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.

Vendor unknown
Product download manager
Published Sep 27, 2026
Stay Ahead of the Next One

Get instant alerts for unknown download manager

Be the first to know when new unknown vulnerabilities affecting unknown download manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Download Manager
4.0.0 < 7.5.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/85ebf2d8-af69-434c-b733-8156210d6d6a/

Credits

Andy WPScan