Impact
The vulnerability allows authenticated contributors or higher to store malicious scripts via the ‘regurl’ attribute in Download Manager’s login-form template. The payload executes in browsers of logged‑out visitors to pages containing the injected content, compromising confidentiality and integrity of those sites. The flaw results from missing input sanitization and inadequate output escaping, as reflected by the CWE‑79 classification.
Affected Systems
WordPress installations utilizing the codename065:Download Manager plugin, any version up to and including 3.3.71, are affected. Users with contributor or higher privileges can inject code; visitors who are not logged in become vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. EPSS data is unavailable, so the exploitation probability is unclear, and the vulnerability is not listed in CISA KEV. The attack vector likely involves authenticated users creating or editing content that renders the injected script to unauthenticated viewers, bypassing the typical delivery of a different template for logged‑in users.
OpenCVE Enrichment