WordPress Plugin Vulnerabilities

Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription

Description

The plugin does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free plugin published under the same slug does not ship the affected feature.

Proof of Concept

Affects Plugins

Fixed in 7.5.6

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Andy
Submitter
Andy
Verified
Yes

Timeline

Publicly Published
2026-09-25 (about 2 days ago)
Added
2026-09-25 (about 1 day ago)
Last Updated
2026-09-26 (about 8 hours ago)

Other