Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw in the WordPress plugin m1.DownloadList from maennchen1.de. Improper handling of user‑supplied input allows an attacker to inject arbitrary JavaScript that executes within the victim’s browser session, potentially enabling cookie theft, defacement, or execution of malicious payloads. This weakness is classified as CWE‑79.
Affected Systems
WordPress installations that use the m1.DownloadList plugin from vendor maennchen1.de and run any released version through 0.19. Users operating version 0.19 or older are vulnerable; newer releases are not listed as affected.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity, while the EPSS score of less than 1 % indicates that exploitation is considered unlikely but still possible. The vulnerability is not currently listed in the CISA KEV catalog. The most probable attack vector involves a user visiting a page that contains crafted input—for example, clicking a malicious link or submitting a form that triggers the DOM‑based XSS.
OpenCVE Enrichment
EUVD