PatchSiren

Shahjada CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Shahjada CVE published 2026-04-08

CVE-2026-39676

A Missing Authorization vulnerability exists in the Download Manager plugin for WordPress, affecting versions from n/a through 3.3.52. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 5.3 and a severity of MEDIUM. The vulnerability has a medium priority due to its CVSS score and severity. Users of the Download Manager plugin for WordPress should [truncated]

MEDIUM Shahjada CVE published 2026-04-08

CVE-2026-39615

A Stored XSS vulnerability was found in the Download Manager plugin, affecting versions up to 3.3.53. This issue allows an attacker to inject malicious scripts into web pages, potentially leading to unauthorized actions or data theft. The vulnerability is caused by improper neutralization of input during web page generation, classified as CWE-79. The CVSS score is 5.9, with a severity of MEDIUM. The vulne [truncated]