SECURITYHIGHCVE-2026-86609

Unauthenticated Stored XSS in Download Manager Pro Subscription Form (CVE-2026-86609)

Download Manager Pro fails to sanitize its email-locked subscription form, letting unauthenticated attackers plant stored XSS against admins.

Dylan H.

Security Team

September 27, 2026
4 min read
Unauthenticated Stored XSS in Download Manager Pro Subscription Form (CVE-2026-86609)

Affected Products

  • Download Manager Pro, 4.0.0 and later, before 7.5.6 (email-locked download subscription feature)

Executive Summary

An unauthenticated stored cross-site scripting vulnerability (CVE-2026-86609) has been disclosed in the Pro edition of the Download Manager WordPress plugin. The flaw is in the email-locked download subscription form — a public-facing feature that lets visitors unlock a download by submitting their email address. The plugin does not sanitize or escape that submitted data before echoing it back on an admin-facing subscriptions page. Because the form requires no login, any unauthenticated attacker can submit a malicious payload; the stored script then executes in an administrator's browser session the next time they view the subscriptions page in wp-admin.

CVSS Score: 8.8 (High, CVSS 3.1)


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-86609
CVSS Score8.8 (High), CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
TypeStored Cross-Site Scripting (CWE-79)
Attack SurfacePublic-facing email-locked download subscription form
Privileges RequiredNone — attacker-facing form requires no authentication
User InteractionRequired — an administrator must view the affected admin page
Public ExploitNot observed as of publication
AssignerWPScan (CVE reserved 2026-09-08)
Published2026-09-27

Affected Products

Plugin / EditionAffected VersionsFixed VersionInstall Base
Download Manager Pro (email-locked subscription feature)4.0.0 and later, before 7.5.67.5.6Free base plugin (same slug) has 100,000+ active installs; Pro-specific counts are not published separately

The vulnerable feature — email-locked downloads — is a Pro-only capability. Sites running only the free Download Manager plugin without the Pro add-on are not exposed to this specific flaw.


Technical Details

Root Cause

The subscription form captures a visitor's email address (and any other submitted field values) to grant access to a locked download. That input is stored and later rendered on an administrator-facing subscriptions management page inside wp-admin without output encoding. Because the intake form is public and requires no account, the trust boundary between anonymous visitor input and administrator-viewed output is effectively broken.

Attack Chain

1. Attacker locates a WordPress site running Download Manager Pro
   with an email-locked download active
 
2. Attacker submits the subscription form with a malicious script
   payload in place of (or alongside) the expected email value
 
3. The plugin stores the unsanitized value tied to the subscription
   record
 
4. An administrator opens the plugin's subscriptions/admin page;
   the stored payload executes in their authenticated browser
   session
 
5. The attacker's script can perform any action the admin's
   session permits — e.g. creating a new admin user, modifying
   site settings, or exfiltrating admin cookies/nonces

Impact Assessment

Impact AreaDescription
Administrator Account TakeoverScript execution in an admin session can be used to create rogue administrator accounts
No Authentication BarrierAttackers need no account of any kind to plant the payload
Site-Wide ControlSuccessful exploitation can lead to full site compromise via the admin session
Silent TriggerThe victim (administrator) simply needs to view a normal admin page to trigger execution

Recommendations

Immediate Actions

  1. Update Download Manager Pro to version 7.5.6 or later immediately.
  2. Review existing subscription/download-unlock records for suspicious entries containing HTML or script-like content, and purge them.
  3. Rotate WordPress admin credentials and session/auth cookies if any administrator viewed the subscriptions page after the plugin's public disclosure or during an active campaign window.
  4. Temporarily disable email-locked downloads if immediate patching isn't possible.

Detection

  • Search subscription/download-unlock database tables for values containing script tags, onerror=, onload=, or other HTML/JS markers.
  • Review recent WordPress admin user creation and role-change events for anything unexpected.

References