← Back to search

CVE-2026-86609

8.8 HIGH

Published 2026-09-27 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) attacks by injecting malicious scripts through the email-locked download subscription form, which could lead to data exfiltration, information disclosure, and potential administrative control.
Exploitability
Exploitation is relatively easy as it requires submitting a payload through the subscription form. Attackers must have access to the form and be able to submit data.
Blast radius
If exploited, the attack could impact all administrators who visit the affected admin page, potentially leading to widespread data compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Download Manager WordPress plugin version 7.5.6 or later.
xsswebwordpressadmin

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-79

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.