CVE-2026-9696: Download Manager <= 3.3.58 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_packages Shortcode
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notfound' parameter in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require administrator privileges or interaction from the attacker?
No administrator privileges are required. An authenticated WordPress user with Contributor-level access or higher can exploit the issue over the network with low attack complexity and no user interaction required from the attacker.
Who is affected after malicious content is injected?
Any user who accesses a page containing the injected content may execute the attacker’s script in their browser. The vulnerability has changed scope and can affect the confidentiality and integrity of the viewing user’s session or data.