CVE-2026-1666 | Download Manager Plugin up to 3.3.46 on WordPress Shortcode redirect_to cross site scripting
A vulnerability, which was classified as problematic, was found in Download Manager Plugin up to 3.3.46 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. Executing a manipulation of the argument redirect_to can lead to cross site scripting.
This vulnerability is registered as CVE-2026-1666. It is possible to launch the attack remotely. No exploit is available.