CVE-2026-14292: WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14292?
CVE-2026-14292 has a risk score of 43, indicating a moderate severity level.
How do I fix CVE-2026-14292?
To fix CVE-2026-14292, update the WordPress Download Manager plugin to version 3.3.66 or later.
Who is affected by CVE-2026-14292?
CVE-2026-14292 affects users with the Author role or higher in WordPress installations using the vulnerable Download Manager plugin.
What type of vulnerability is CVE-2026-14292?
CVE-2026-14292 is a Stored Cross-Site Scripting (XSS) vulnerability that allows arbitrary JavaScript execution.
What can an attacker do with CVE-2026-14292?
An attacker exploiting CVE-2026-14292 can execute arbitrary JavaScript in the browsers of users viewing the affected package titles.