SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14292

MEDIUM · CVSS 5.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Download Manager WordPress plugin prior to version 3.3.66 is vulnerable due to improper escaping of package titles, enabling users with Author privileges or higher to inject arbitrary JavaScript into front-end templates. This flaw poses a risk of cross-site scripting (XSS) attacks, potentially affecting any user, including unauthenticated visitors, who views the compromised package. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-14292
Severity
MEDIUM
CVSS
5.4
EPSS
0.15%
WordPress Java

Original NVD Description

The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.