Skip to content
Threat Feed
high advisory

Stored XSS in Download Monitor WordPress Plugin (CVE-2026-100182)

The Download Monitor plugin for WordPress versions up to 5.2.10 is vulnerable to Stored Cross-Site Scripting via a malicious postMessage injection that executes when an administrator interacts with a compromised download object.

CVE search metadata

CVE search record: CVE-2026-100182. Severity: high. CVSS: 7.2. KEV: no. Product: Download Monitor (<= 5.2.10). Brief: Stored XSS in Download Monitor WordPress Plugin (CVE-2026-100182). Brief link: https://feed.craftedsignal.io/briefs/2026-10-download-monitor-xss/

The Download Monitor plugin for WordPress, in all versions up to and including 5.2.10, contains a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-100182). This vulnerability arises from insufficient input sanitization and output escaping when handling Cross-Origin postMessage communications directed at the Admin Editor. An unauthenticated attacker can orchestrate an attack by deceiving an authenticated administrator into visiting an attacker-controlled website while the administrator has an active WordPress Download edit screen open in another tab.

The browser, following the postMessage instructions, triggers the injection of malicious web scripts into the download data. Because the administrator possesses the 'unfiltered_html' capability, WordPress permits the storage of this malicious payload. Once the payload is saved, it is later emitted verbatim to the frontend whenever the [download_data] shortcode is rendered. This allows for unauthorized script execution in the context of victim browsers visiting the compromised site.

Attack Chain

  1. Attacker hosts a malicious website containing an iFrame or script designed to send a crafted cross-origin postMessage.
  2. Attacker lures an authenticated WordPress Administrator to visit the malicious website.
  3. The malicious website identifies the administrator's session and targets the open WordPress admin panel (e.g., the Download edit screen).
  4. The malicious page sends a cross-origin postMessage containing a script payload to the admin panel.
  5. The Download Monitor plugin fails to sanitize the incoming postMessage, causing the payload to be injected into the Download edit field.
  6. The administrator, having 'unfiltered_html' permissions, saves the download object, causing the malicious script to be persisted in the WordPress database.
  7. When a user visits a page containing the [download_data] shortcode, the server renders the payload.
  8. The victim's browser executes the script in the context of the WordPress site.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's browser session. This can lead to session hijacking, unauthorized actions performed on behalf of the user, or redirection to further malicious content. All websites running Download Monitor version 5.2.10 or earlier are at risk of this stored XSS, which potentially affects any visitor to the site.

Recommendation

Update the Download Monitor plugin to the latest patched version immediately (version 5.2.11 or higher is recommended once available). In the absence of an immediate patch, restrict access to the WordPress admin panel via IP allowlisting and monitor access logs for anomalous POST requests to the download management endpoints. Since this is an application-level XSS vulnerability, ensure that Content Security Policy (CSP) headers are strictly configured to prevent the execution of inline scripts and unauthorized external resources.


Immediate actions

Audit and update Download Monitor plugin to a version > 5.2.10.

IT Operations 48h

Mitigations

Enforce strict Content Security Policy (CSP) to restrict script sources.

immediate IT Operations

CVE-2026-100182