Executive Summary
An unauthenticated stored cross-site scripting vulnerability (CVE-2026-86609) has been disclosed in the Pro edition of the Download Manager WordPress plugin. The flaw is in the email-locked download subscription form — a public-facing feature that lets visitors unlock a download by submitting their email address. The plugin does not sanitize or escape that submitted data before echoing it back on an admin-facing subscriptions page. Because the form requires no login, any unauthenticated attacker can submit a malicious payload; the stored script then executes in an administrator's browser session the next time they view the subscriptions page in wp-admin.
CVSS Score: 8.8 (High, CVSS 3.1)
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-86609 |
| CVSS Score | 8.8 (High), CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Type | Stored Cross-Site Scripting (CWE-79) |
| Attack Surface | Public-facing email-locked download subscription form |
| Privileges Required | None — attacker-facing form requires no authentication |
| User Interaction | Required — an administrator must view the affected admin page |
| Public Exploit | Not observed as of publication |
| Assigner | WPScan (CVE reserved 2026-09-08) |
| Published | 2026-09-27 |
Affected Products
| Plugin / Edition | Affected Versions | Fixed Version | Install Base |
|---|---|---|---|
| Download Manager Pro (email-locked subscription feature) | 4.0.0 and later, before 7.5.6 | 7.5.6 | Free base plugin (same slug) has 100,000+ active installs; Pro-specific counts are not published separately |
The vulnerable feature — email-locked downloads — is a Pro-only capability. Sites running only the free Download Manager plugin without the Pro add-on are not exposed to this specific flaw.
Technical Details
Root Cause
The subscription form captures a visitor's email address (and any other submitted field values) to grant access to a locked download. That input is stored and later rendered on an administrator-facing subscriptions management page inside wp-admin without output encoding. Because the intake form is public and requires no account, the trust boundary between anonymous visitor input and administrator-viewed output is effectively broken.
Attack Chain
1. Attacker locates a WordPress site running Download Manager Pro
with an email-locked download active
2. Attacker submits the subscription form with a malicious script
payload in place of (or alongside) the expected email value
3. The plugin stores the unsanitized value tied to the subscription
record
4. An administrator opens the plugin's subscriptions/admin page;
the stored payload executes in their authenticated browser
session
5. The attacker's script can perform any action the admin's
session permits — e.g. creating a new admin user, modifying
site settings, or exfiltrating admin cookies/noncesImpact Assessment
| Impact Area | Description |
|---|---|
| Administrator Account Takeover | Script execution in an admin session can be used to create rogue administrator accounts |
| No Authentication Barrier | Attackers need no account of any kind to plant the payload |
| Site-Wide Control | Successful exploitation can lead to full site compromise via the admin session |
| Silent Trigger | The victim (administrator) simply needs to view a normal admin page to trigger execution |
Recommendations
Immediate Actions
- Update Download Manager Pro to version 7.5.6 or later immediately.
- Review existing subscription/download-unlock records for suspicious entries containing HTML or script-like content, and purge them.
- Rotate WordPress admin credentials and session/auth cookies if any administrator viewed the subscriptions page after the plugin's public disclosure or during an active campaign window.
- Temporarily disable email-locked downloads if immediate patching isn't possible.
Detection
- Search subscription/download-unlock database tables for values containing
scripttags,onerror=,onload=, or other HTML/JS markers. - Review recent WordPress admin user creation and role-change events for anything unexpected.