In Download Manager plugin for WordPress versions up to and including 3.3.18 a medium severity vulnerability CVE-2025-4367 was detected. This vulnerability allows authenticated attackers with Author-level access and above to inject arbitrary web scripts via the wpdm_user_dashboard shortcode, due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Download Manager plugin to versions 3.3.19 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4367.
WordPress: Stored XSS via Shortcode in Download Manager Plugin
by the Hossted team
19.06.2025