rootpwn

medium · CVSS v3 6.4 · EPSS 0.00216

CVE-2026-97338

The Download Manager plugin for WordPress is vulnerable to stored XSS via the display name field. Authenticated subscribers can inject scrip

Overview

The Download Manager plugin for WordPress is vulnerable to stored XSS via the display name field. Authenticated subscribers can inject scripts that run when other users view pages containing the wpdm_edit_profile shortcode. This allows attackers to steal credentials or deface sites.

Description

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the [wpdm_edit_profile] shortcode to be present on a front-end page accessible to Subscriber-level users, who can then submit a multiply entity-encoded payload via the display name field to bypass sanitization.

Impact

Confidentiality: attackers can steal session cookies or other sensitive data. Integrity: injected scripts can modify page content. Availability: minimal. Impacted parties: site administrators, subscribers, and visitors who load affected pages.

Remediation

Update the plugin to version 3.3.71 or later. If update is not possible, disable the wpdm_edit_profile shortcode on public pages or restrict subscriber access to that shortcode. Ensure input sanitization by using wp_kses_post or similar. Monitor for malicious scripts in user display names.

Risk context

The CVE has a medium severity score (6.4) and a very low EPSS of 0.00216, indicating a low likelihood of exploitation in the wild, but defenders should still patch promptly to mitigate potential XSS attacks.

Affected products

  • WordPress Download Manager
  • WordPress

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
6.4
CVSS v4
—
EPSS
0.00216

XSS Stored XSS WordPress Download Manager Subscriber Input Sanitization Web Security

← All CVEs