CVE-2019-15889
The Download Manager plugin before version 2.9.94 contains a reflected cross-site scripting vulnerability in its Category Short-code feature, which processes user input through the orderby parameter without proper sanitization. An attacker can inject malicious JavaScript by manipulating the orderby parameter with payloads such as "> followed by script tags, causing the payload to execute in a user's browser. The same vulnerability also exists in the Advanced Search functionality, allowing for similar exploitation through unsanitized input handling.
Based on public CVE data (MITRE/NVD).