{"id":"CVE-2026-86609","title":"The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to…","summary":"The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to…","severity":"none","cwe":["CWE-79"],"product":"Download Manager","affected":["download_manager >= 4.0.0 < 7.5.6"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T06:17:14.070","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86609","references":[{"url":"https://wpscan.com/vulnerability/85ebf2d8-af69-434c-b733-8156210d6d6a/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T06:43:46.829Z","slug":"CVE-2026-86609","body":"## Overview\n\nThe Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}