nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-1666 CVE-2026-1666
MEDIUM
Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter
Record summary
CVE-2026-1666 has a selected CVSS score of 6.1 (medium).
Description
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Download ManagerBrowse codename065 / Download ManagerDefault status: unaffected | CVE List | Through 3.3.46 | affected |
References
6plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.46/src/User/Login.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.46/src/User/views/login-form.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3455081%40download-manager%2Ftrunk&old=3440008%40download-manager%2Ftrunk&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/3cb84ba3-b403-4a9d-b1a7-92aa947310ac?source=cve wpdownloadmanager.com
https://www.wpdownloadmanager.com/doc/short-codes/wpdm_login_form-user-login-form-short-code