{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-86609","assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","state":"PUBLISHED","assignerShortName":"WPScan","dateReserved":"2026-09-08T08:47:55.555Z","datePublished":"2026-09-27T06:00:19.713Z","dateUpdated":"2026-09-27T06:00:19.713Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan","dateUpdated":"2026-09-27T06:00:19.713Z"},"title":"Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription","problemTypes":[{"descriptions":[{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}]}],"affected":[{"vendor":"Unknown","product":"Download Manager","versions":[{"status":"affected","versionType":"semver","version":"4.0.0","lessThan":"7.5.6"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature."}],"references":[{"url":"https://wpscan.com/vulnerability/85ebf2d8-af69-434c-b733-8156210d6d6a/","tags":["exploit","vdb-entry","technical-description"]}],"credits":[{"lang":"en","value":"Andy","type":"finder"},{"lang":"en","value":"WPScan","type":"coordinator"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"WPScan CVE Generator"}}}}