Impact
The Download Manager plugin for WordPress has a flaw that allows an attacker with Contributor or higher privileges to store arbitrary JavaScript in the 'not_found' parameter of the wpdm_packages shortcode. This stored script is rendered on pages that include the shortcode, enabling the attacker to run malicious code in the browsers of any visitor who views the affected content. The vulnerability is a classic XSS weakness (CWE‑79) caused by insufficient input sanitization and output escaping.
Affected Systems
WordPress sites that use the Download Manager plugin version 3.3.58 or earlier are impacted. The CNA identifies the product as codename065:Download Manager. If the wpdm_packages shortcode is exposed to authenticated users, any installation of these versions is vulnerable.
Risk and Exploitability
The CVSS base score of 6.4 signifies a moderate level of severity. EPSS data is not supplied, so the likelihood of exploitation remains unknown. The flaw is not listed in CISA KEV. The attack path requires authenticated Contributor‑level access and the ability to edit or create content that will be stored in the database. Once an attacker injects malicious script, it will run for all users who view the affected page, potentially compromising session cookies, defacing content, or serving additional malware. The likely attack vector is via content creation or editing by an authorized contributor.
OpenCVE Enrichment