medium · CVSS v3 6.4 · EPSS 0.00216
CVE-2026-97338
The Download Manager plugin for WordPress is vulnerable to stored XSS via the display name field. Authenticated subscribers can inject scrip
Overview
The Download Manager plugin for WordPress is vulnerable to stored XSS via the display name field. Authenticated subscribers can inject scripts that run when other users view pages containing the wpdm_edit_profile shortcode. This allows attackers to steal credentials or deface sites.
Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the [wpdm_edit_profile] shortcode to be present on a front-end page accessible to Subscriber-level users, who can then submit a multiply entity-encoded payload via the display name field to bypass sanitization.
Impact
Confidentiality: attackers can steal session cookies or other sensitive data. Integrity: injected scripts can modify page content. Availability: minimal. Impacted parties: site administrators, subscribers, and visitors who load affected pages.
Remediation
Update the plugin to version 3.3.71 or later. If update is not possible, disable the wpdm_edit_profile shortcode on public pages or restrict subscriber access to that shortcode. Ensure input sanitization by using wp_kses_post or similar. Monitor for malicious scripts in user display names.
Risk context
The CVE has a medium severity score (6.4) and a very low EPSS of 0.00216, indicating a low likelihood of exploitation in the wild, but defenders should still patch promptly to mitigate potential XSS attacks.
Affected products
- WordPress Download Manager
- WordPress
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 6.4
- CVSS v4
- —
- EPSS
- 0.00216