OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-86609

HIGH · CVSS 8.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Download Manager WordPress plugin, specifically in its commercial Pro edition prior to version 7.5.6, is vulnerable due to inadequate sanitization and escaping of data in its email-locked download subscription form. This flaw could enable unauthenticated attackers to execute Stored Cross-Site Scripting (XSS) attacks against administrators, potentially compromising site security. Administrators using the affected Pro edition should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-86609
Severity
HIGH
CVSS
8.8
EPSS
0.28%
WordPress

Original NVD Description

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.