Vulnerability Description
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-14292?
CVE-2026-14292 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to ...
How severe is CVE-2026-14292?
CVE-2026-14292 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14292?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.