{"id":"CVE-2026-86609","published":"2026-09-27T06:17:14.070","lastModified":"2026-09-28T16:38:58.950","description":"The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/85ebf2d8-af69-434c-b733-8156210d6d6a/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) attacks by injecting malicious scripts through the email-locked download subscription form, which could lead to data exfiltration, information disclosure, and potential administrative control.","exploitability":"Exploitation is relatively easy as it requires submitting a payload through the subscription form. Attackers must have access to the form and be able to submit data.","blast_radius":"If exploited, the attack could impact all administrators who visit the affected admin page, potentially leading to widespread data compromise.","remediation":"Upgrade to Download Manager WordPress plugin version 7.5.6 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["xss","web","wordpress","admin"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:05:03.801Z"}}