CVE-2022-45836
The Download Manager plugin for WordPress contains reflected cross-site scripting vulnerabilities in multiple files including packages-shortcode-toolbar.php, Shortcodes.php, and category-shortcode-toolbar.php located within the src/Package/views/ and src/Category/views/ directories, affecting versions through 3.2.59. The vulnerabilities stem from inadequate sanitization of user input and insufficient escaping of output, allowing unauthenticated attackers to inject malicious scripts that execute when a user visits a specially crafted link. The flaw was remedied in version 3.2.60 or later.
Based on public CVE data (MITRE/NVD).