Executive brief
The Download Manager plugin for WordPress, which is used to manage and track file downloads, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users or administrators visit these affected pages, the scripts will execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'sid' attribute of the 'wpdm_members' shortcode. The vulnerability exists in the members() function where the 'sid' parameter is extracted and stored via update_post_meta() without sanitization. Subsequently, the value is echoed directly into an HTML ID attribute in the members.php template without using esc_attr(). An authenticated attacker with contributor-level permissions or higher can exploit this to inject malicious JavaScript. The vulnerability is fixed in versions following 3.3.52.
Affected products
- codename065 Download Manager up to and including 3.3.52
Timeline
- 2026-04-09: disclosed: Initial disclosure by Wordfence
- 2026-04-09: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.51/src/User/User.php
- https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.51/src/User/views/members.php
- https://plugins.trac.wordpress.org/browser/download-manager/trunk/src/User/User.php
- https://plugins.trac.wordpress.org/browser/download-manager/trunk/src/User/views/members.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3501300%40download-manager&new=3501300%40download-manager&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/27fc81b0-c03a-4de7-bc38-791401d1685b?source=cve