Impact
The vulnerability lies in the Download Manager Pro WordPress plugin before version 7.5.6. Data entered through the email‑locked download subscription form is stored by the plugin and later output on an admin‑page without proper sanitisation or escaping. This flaw allows an attacker to inject arbitrary JavaScript that will execute in the browser context of any WordPress administrator who views the affected admin page, enabling malicious actions such as session hijacking, credential theft, or defacement, all while remaining hidden from users.
Affected Systems
Affects the commercial Download Manager Pro WordPress plugin with any release earlier than 7.5.6. The free (non‑Pro) Download Manager plugin, though released under the same slug, does not include the vulnerable subscription feature and is therefore not impacted.
Risk and Exploitability
Exploitability is high because the attack requires no authentication; any person with internet access can submit a malicious payload via the public subscription form. The lack of a published CVSS score or EPSS data suggests the severity is not formally quantified, but the nature of stored XSS in an admin interface is considered a significant risk. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploits at the time of assessment. Adopting the safest assumption, an attacker could deliver scripts that persist across administrative sessions and could persist until the plugin is updated or the issue is otherwise mitigated.
OpenCVE Enrichment