{"id":"CVE-2026-14292","title":"The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitra…","summary":"The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitra…","severity":"none","published":"2026-08-01","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14292","references":[{"url":"https://wpscan.com/vulnerability/719b6675-7891-4742-9751-bba2e72414a8/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00155,"epssPercentile":0.05022,"ingestedAt":"2026-08-02T03:17:05.908Z","slug":"CVE-2026-14292","body":"## Overview\n\nThe Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}