CVE · Medium

CVE-2026-14343 — Download Manager [download-manager] < 3.3.62

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14343 Download Manager [download-manager] < 3.3.62 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.3.62 3.3.62 2026-06-30

CVE-2026-14343

The Download Manager plugin for WordPress contains a vulnerability that allows an authenticated attacker with contributor-level access or higher to inject malicious web scripts into pages. This is due to inadequate filtering of user input in the 'note_before' and 'note_after' shortcode attributes, which can lead to stored cross-site scripting. When a user visits the affected page, the injected scripts will execute, potentially compromising the security of the WordPress site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.