CVE-2026-86609

CVE-2026-86609 published: The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cros...

View full NVD advisory → ← Back to CVE watch