PT-2026-67122 · WordPress · Download Manager

·

CVE-2026-16685

·

Published

2026-08-01

·

Updated

2026-08-03

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Download Manager versions prior to 3.3.67
Description The Download Manager plugin for WordPress contains a Stored Cross-Site Scripting issue. Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages. This occurs because the icon shortcode attribute is not properly sanitized or escaped during rendering. The wp kses post() function fails to neutralize the payload as it processes post content during the save process rather than handling shortcode attribute values emitted at render time.
Recommendations Update to a version newer than 3.3.66. As a temporary mitigation, restrict the use of the icon attribute within shortcodes for users with contributor-level access.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16685

Affected Products

Download Manager