Junglewise Threat Intelligence

CVE-2026-39615: Shahjada Download Manager Stored XSS in WordPress plugin

CVE-2026-39615 · Severity: medium · CVSS 5.9 · Published 2026-04-08

Technologies: Shahjada (W3 Eden) Download Manager.

Executive brief

The Download Manager plugin for WordPress, used to manage and track file downloads, is vulnerable to a security flaw that allows high-privileged users to inject malicious scripts into the website. If exploited, these scripts could be used to redirect visitors to malicious sites, display unauthorized advertisements, or perform actions on behalf of other site administrators. This risk is primarily realized when an administrator interacts with a malicious link or page created by an attacker with 'Author' level access.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Shahjada Download Manager plugin (download-manager) for WordPress. The flaw stems from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject persistent malicious scripts. Exploitation requires 'Author' or higher privileges and involves a victim (typically another administrator) interacting with a crafted page or link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized site modifications. The issue is addressed in version 3.3.54.

Affected products

  • Shahjada (W3 Eden) Download Manager <= 3.3.53

Timeline

  • 2026-01-11: other: Vulnerability reported by researcher hhhai
  • 2026-02-10: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE-2026-39615 published
  • 2026-02-10: patched: Version 3.3.54 released to address the issue

References