{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/download-monitor--5.2.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:download_monitor:download_monitor:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-100182"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Download Monitor (\u003c= 5.2.10)"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","cve-2026-100182"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Download Monitor plugin for WordPress, in all versions up to and including 5.2.10, contains a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-100182). This vulnerability arises from insufficient input sanitization and output escaping when handling Cross-Origin postMessage communications directed at the Admin Editor. An unauthenticated attacker can orchestrate an attack by deceiving an authenticated administrator into visiting an attacker-controlled website while the administrator has an active WordPress Download edit screen open in another tab.\u003c/p\u003e\n\u003cp\u003eThe browser, following the postMessage instructions, triggers the injection of malicious web scripts into the download data. Because the administrator possesses the 'unfiltered_html' capability, WordPress permits the storage of this malicious payload. Once the payload is saved, it is later emitted verbatim to the frontend whenever the [download_data] shortcode is rendered. This allows for unauthorized script execution in the context of victim browsers visiting the compromised site.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker hosts a malicious website containing an iFrame or script designed to send a crafted cross-origin postMessage.\u003c/li\u003e\n\u003cli\u003eAttacker lures an authenticated WordPress Administrator to visit the malicious website.\u003c/li\u003e\n\u003cli\u003eThe malicious website identifies the administrator's session and targets the open WordPress admin panel (e.g., the Download edit screen).\u003c/li\u003e\n\u003cli\u003eThe malicious page sends a cross-origin postMessage containing a script payload to the admin panel.\u003c/li\u003e\n\u003cli\u003eThe Download Monitor plugin fails to sanitize the incoming postMessage, causing the payload to be injected into the Download edit field.\u003c/li\u003e\n\u003cli\u003eThe administrator, having 'unfiltered_html' permissions, saves the download object, causing the malicious script to be persisted in the WordPress database.\u003c/li\u003e\n\u003cli\u003eWhen a user visits a page containing the [download_data] shortcode, the server renders the payload.\u003c/li\u003e\n\u003cli\u003eThe victim's browser executes the script in the context of the WordPress site.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's browser session. This can lead to session hijacking, unauthorized actions performed on behalf of the user, or redirection to further malicious content. All websites running Download Monitor version 5.2.10 or earlier are at risk of this stored XSS, which potentially affects any visitor to the site.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Download Monitor plugin to the latest patched version immediately (version 5.2.11 or higher is recommended once available). In the absence of an immediate patch, restrict access to the WordPress admin panel via IP allowlisting and monitor access logs for anomalous POST requests to the download management endpoints. Since this is an application-level XSS vulnerability, ensure that Content Security Policy (CSP) headers are strictly configured to prevent the execution of inline scripts and unauthorized external resources.\u003c/p\u003e\n","date_modified":"2026-10-02T08:23:19Z","date_published":"2026-10-02T08:23:19Z","id":"https://feed.craftedsignal.io/briefs/2026-10-download-monitor-xss/","summary":"The Download Monitor plugin for WordPress versions up to 5.2.10 is vulnerable to Stored Cross-Site Scripting via a malicious postMessage injection that executes when an administrator interacts with a compromised download object.","title":"Stored XSS in Download Monitor WordPress Plugin (CVE-2026-100182)","url":"https://feed.craftedsignal.io/briefs/2026-10-download-monitor-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Download Monitor (\u003c= 5.2.10)","version":"https://jsonfeed.org/version/1.1"}