CVE-2026-86609
8.8 HIGHPublished 2026-09-27 · Updated 2026-09-28
AI risk analysis
- Summary
- The flaw allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) attacks by injecting malicious scripts through the email-locked download subscription form, which could lead to data exfiltration, information disclosure, and potential administrative control.
- Exploitability
- Exploitation is relatively easy as it requires submitting a payload through the subscription form. Attackers must have access to the form and be able to submit data.
- Blast radius
- If exploited, the attack could impact all administrators who visit the affected admin page, potentially leading to widespread data compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Download Manager WordPress plugin version 7.5.6 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-79
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-63459PoC
- CRITICALCVE-2026-85385
- HIGHCVE-2026-92438
- HIGHCVE-2026-93923PoC
- MEDIUMCVE-2025-71419PoC
- HIGHCVE-2026-16143
- CRITICALCVE-2026-18872
- MEDIUMCVE-2026-36468PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.