CVE-2026-86610

CVE-2026-86610 published: The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks agains...

View full NVD advisory → ← Back to CVE watch