Impact
The vulnerability arises because the Download Manager WordPress plugin fails to sanitize a package setting value that is then displayed in the package download dialog. A user with the Author role or higher can embed malicious script content in the package icon metadata, and when any visitor—including administrators—opens the download dialog, the unescaped content executes in the visitor’s browser. The flaw is an instance of stored cross‑site scripting, allowing the attacker to hijack user sessions, deface sites, or exfiltrate data.
Affected Systems
Any WordPress installation running the Download Manager plugin at a version earlier than 3.3.71 with PHP 5.6 through 8.0. The issue applies to all users who can configure a package icon and to all site visitors who access the download dialogue. Sites using PHP 8.1 or later are not affected because the sanitisation in newer PHP versions neutralises the problematic single quotes.
Risk and Exploitability
No CVSS score is publicly available, and the EPSS score is unavailable, so the precise exploitation probability cannot be quantified. The vulnerability is present in all affected installations regardless of network exposure, as the attack relies on local content manipulation by an Author role user and does not require external access. The flaw is listed in CISA KEV as not yet listed, indicating no documented widespread exploitation at this time. An attacker with sufficient permissions can create or modify a package icon containing malicious payloads; any site visitor opening that dialog will have the script executed in their browser context.
OpenCVE Enrichment