PT-2026-31571 · WordPress · Download Manager

Djaidja Moundjid

·

Published

2026-04-09

·

Updated

2026-04-19

·

CVE-2026-5357

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Download Manager plugin for WordPress versions up to and including 3.3.52
Description The Download Manager plugin for WordPress is susceptible to Stored Cross-Site Scripting through the sid parameter of the 'wpdm members' shortcode. This occurs because of inadequate input sanitization and output escaping of the user-supplied sid shortcode attribute. The sid parameter is extracted without sanitization within the members() function and stored using update post meta(), then directly echoed into an HTML id attribute in the members.php template without esc attr(). This allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which will execute when a user accesses the affected page.
Recommendations Download Manager plugin for WordPress version 3.3.53 and later Disable the 'wpdm members' shortcode if it is not required Sanitize and escape the sid parameter before using it in the 'wpdm members' shortcode

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-5357

Affected Products

Download Manager