CVE-2026-86610
Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue, including administrators. Only sites running PHP below 8.1 are affected, as the sanitisation applied when the setting is saved does not neutralise single quotes there.
| Vendor | unknown |
| Product | download manager |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown download manager
Be the first to know when new unknown vulnerabilities affecting unknown download manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Download Manager
0 < 3.3.71
References
Credits
Mark Moore WPScan