CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86609

UNKNOWNCVSS 0NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administra

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-86609 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86609

UNKNOWNCVSS 0NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administra

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]