What is CVE-2026-14292?
CVE-2026-14292 is a stored Cross-Site Scripting (XSS) vulnerability in the Download Manager WordPress plugin before version 3.3.66. Authenticated users with Author role or higher can inject arbitrary JavaScript by failing to properly escape a package's title, which executes in the browser of any user viewing the front-end package template. Updating to the latest plugin version is advised.
Azərbaycanca: CVE-2026-14292, Download Manager WordPress plaginində (3.3.66 versiyasından əvvəl) aşkarlanmış saxlanılmış XSS zəifliyidir. Bu boşluq Author və ya daha yuxarı rol sahibi istifadəçilərə paket başlığında zərərli JavaScript kodu yerləşdirərək, həmin başlığa baxan istənilən istifadəçinin brauzerində kod icrasına səbəb olur. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by CVE-2026-14292?
This vulnerability is found in the Download Manager WordPress plugin before version 3.3.66.
What privilege level is required to exploit CVE-2026-14292?
An attacker must be an authenticated user with at least the Author role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.