WordPress Plugin Vulnerabilities
Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription
Description
The plugin does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free plugin published under the same slug does not ship the affected feature.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Andy
Submitter
Andy
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-25 (about 2 days ago)
Added
2026-09-25 (about 1 day ago)
Last Updated
2026-09-26 (about 8 hours ago)