CVE-2026-39615: WordPress Download Manager plugin <= 3.3.53 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download Manager download-manager allows Stored XSS.This issue affects Download Manager: from n/a through <= 3.3.53.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39615?
CVE-2026-39615 has a medium severity rating of 5.9 on the CVSS scale.
How do I fix CVE-2026-39615?
To mitigate CVE-2026-39615, upgrade the Shahjada WordPress Download Manager plugin to version 3.3.54 or later.
What is the impact of CVE-2026-39615 on my website?
CVE-2026-39615 allows for stored Cross-Site Scripting (XSS), potentially enabling attackers to execute malicious scripts on users' browsers.
Which versions are affected by CVE-2026-39615?
CVE-2026-39615 affects all versions of the Shahjada Download Manager plugin from n/a up to and including version 3.3.53.
What is Cross-Site Scripting (XSS) in the context of CVE-2026-39615?
In the context of CVE-2026-39615, Cross-Site Scripting (XSS) is a security vulnerability that allows the injection of malicious scripts into web pages viewed by users.