PT-2026-49622 · WordPress · File Sharing & Download Manager
CVE-2026-10093
·
Published
2026-06-16
·
Updated
2026-06-16
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
File Sharing & Download Manager – User Private Files versions prior to 2.1.7
Description
Insufficient input sanitization and output escaping allow authenticated attackers with subscriber-level access or higher to perform Stored Cross-Site Scripting. This is achieved by injecting arbitrary web scripts through the
fldr ttl parameter, which then execute when a user accesses the affected page.Recommendations
Update to a version later than 2.1.6.
As a temporary workaround, restrict access to the
fldr ttl parameter to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
File Sharing & Download Manager