Impact
The Lana Downloads Manager plugin for WordPress is vulnerable to stored cross‑site scripting because endpoint parameters are not properly sanitized or escaped. This flaw allows an authenticated attacker with administrator‑level or higher privileges to inject arbitrary scripts that will execute for any user who accesses a page containing the injected content. The vulnerability is classified as CWE‑79.
Affected Systems
The vulnerability affects the Lana Downloads Manager plugin version 1.10.0 and all earlier releases. Administrators and users with higher privileges on affected WordPress sites running this plugin are at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% shows a low likelihood of exploitation at the time of this analysis. The flaw is not listed in the CISA KEV catalog. Exploitation requires login as an administrator or higher; the attacker can then craft a malicious request to the vulnerable endpoint to store the script. Once stored, any visitor to the affected page will execute the injected code in their browser.
OpenCVE Enrichment
EUVD