CVE · Medium

CVE-2026-16685 — Download Manager [download-manager] < 3.3.67

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16685 Download Manager [download-manager] < 3.3.67 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.3.67 3.3.67 2026-07-08

CVE-2026-16685

The Download Manager plugin for WordPress contains a security flaw affecting all versions up to 3.3.66, allowing malicious users with contributor-level access or higher to inject unauthorized web code into pages viewed by others. This vulnerability arises from inadequate filtering of input data and failure to properly sanitize the 'icon' shortcode attribute. As a result, injected scripts can execute automatically when targeted pages are accessed.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.