WordPress Plugin Vulnerabilities

Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon

Description

The plugin does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue, including administrators. Only sites running PHP below 8.1 are affected, as the sanitisation applied when the setting is saved does not neutralise single quotes there.

Proof of Concept

Affects Plugins

Fixed in 3.3.71

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Mark Moore
Submitter
Mark Moore
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-29 (about 1 day ago)
Last Updated
2026-09-29 (about 1 day ago)

Other