<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:download_monitor:download_monitor:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adownload_monitordownload_monitorwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 08:23:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adownload_monitordownload_monitorwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Download Monitor WordPress Plugin (CVE-2026-100182)</title><link>https://feed.craftedsignal.io/briefs/2026-10-download-monitor-xss/</link><pubDate>Fri, 02 Oct 2026 08:23:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-download-monitor-xss/</guid><description>The Download Monitor plugin for WordPress versions up to 5.2.10 is vulnerable to Stored Cross-Site Scripting via a malicious postMessage injection that executes when an administrator interacts with a compromised download object.</description><content:encoded><![CDATA[<p>The Download Monitor plugin for WordPress, in all versions up to and including 5.2.10, contains a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-100182). This vulnerability arises from insufficient input sanitization and output escaping when handling Cross-Origin postMessage communications directed at the Admin Editor. An unauthenticated attacker can orchestrate an attack by deceiving an authenticated administrator into visiting an attacker-controlled website while the administrator has an active WordPress Download edit screen open in another tab.</p>
<p>The browser, following the postMessage instructions, triggers the injection of malicious web scripts into the download data. Because the administrator possesses the 'unfiltered_html' capability, WordPress permits the storage of this malicious payload. Once the payload is saved, it is later emitted verbatim to the frontend whenever the [download_data] shortcode is rendered. This allows for unauthorized script execution in the context of victim browsers visiting the compromised site.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker hosts a malicious website containing an iFrame or script designed to send a crafted cross-origin postMessage.</li>
<li>Attacker lures an authenticated WordPress Administrator to visit the malicious website.</li>
<li>The malicious website identifies the administrator's session and targets the open WordPress admin panel (e.g., the Download edit screen).</li>
<li>The malicious page sends a cross-origin postMessage containing a script payload to the admin panel.</li>
<li>The Download Monitor plugin fails to sanitize the incoming postMessage, causing the payload to be injected into the Download edit field.</li>
<li>The administrator, having 'unfiltered_html' permissions, saves the download object, causing the malicious script to be persisted in the WordPress database.</li>
<li>When a user visits a page containing the [download_data] shortcode, the server renders the payload.</li>
<li>The victim's browser executes the script in the context of the WordPress site.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's browser session. This can lead to session hijacking, unauthorized actions performed on behalf of the user, or redirection to further malicious content. All websites running Download Monitor version 5.2.10 or earlier are at risk of this stored XSS, which potentially affects any visitor to the site.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Download Monitor plugin to the latest patched version immediately (version 5.2.11 or higher is recommended once available). In the absence of an immediate patch, restrict access to the WordPress admin panel via IP allowlisting and monitor access logs for anomalous POST requests to the download management endpoints. Since this is an application-level XSS vulnerability, ensure that Content Security Policy (CSP) headers are strictly configured to prevent the execution of inline scripts and unauthorized external resources.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>xss</category><category>cve-2026-100182</category></item></channel></rss>