← back
CVE-2026-14292

WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title

0Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Track
exploitation probability
observed exploitation
nono source reports it
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.