Stored Cross-Site Scripting in Download Manager Plugin for WordPress
CVE-2025-4367
6.4MEDIUM
What is CVE-2025-4367?
The Download Manager plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping in user-supplied attributes of the wpdm_user_dashboard shortcode. This vulnerability affects all versions up to and including 3.3.18. Authenticated attackers with author-level access can exploit this flaw to inject arbitrary scripts, potentially compromising user data and application integrity when the affected pages are accessed.
Affected Version(s)
Download Manager * <= 3.3.18