Download Manager is a widely used WordPress plugin for managing downloadable files and controlling access to them. However, it contains a critical vulnerability, CVE-2024-10706, which allows for Stored Cross-Site Scripting (XSS) attacks. This vulnerability enables attackers to inject malicious JavaScript code into the plugin’s settings, which is then executed when the settings are accessed. This could lead to account takeover, with attackers gaining unauthorized admin access. With over 100,000 active installations, this flaw presents a significant security risk for WordPress websites using Download Manager.
CVE-2024-10706 – Download Manager – Stored XSS to Admin Account Creation – POC
![CVE-2024-10706 – Download Manager – Stored XSS to Admin Account Creation – POC CVE-2024-10706 – Download Manager – Stored XSS to Admin Account Creation – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)