Impact
The Download Monitor plugin for WordPress contains a stored cross‑site scripting vulnerability caused by insufficient input sanitization and output escaping in the Cross‑Origin postMessage interface to the Admin Editor. An unauthenticated attacker can trick an authenticated Administrator into visiting a crafted page that targets an open Download edit screen; the attacker’s JavaScript payload is then persisted via the Administrator’s unfiltered_html capability and later rendered unescaped by the [download_data] shortcode. When users visit pages that include the injected content, the malicious script will execute in their browsers, potentially leading to defacement, credential theft, or session hijacking.
Affected Systems
The vulnerability affects the Download Monitor plugin for WordPress in all versions up to and including 5.2.10. Single instances of installations running these or earlier versions are at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a high potential impact; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to lure an administrator to a specially crafted page, but the attack can be carried out once the payload is stored. Consequently the risk to sites that remain on affected versions is medium‑high, especially if administrators are active and unfiltered_html is enabled.
OpenCVE Enrichment