CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86610

MEDIUMCVSS 6.4NVD feed

Published 1 October 2026 · tracked since 1 October 2026

Description

The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's downl

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-86610 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86610

MEDIUMCVSS 6.4NVD feed

Published 1 October 2026 · tracked since 1 October 2026

Description

The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's downl

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]