A vulnerability was found in codename065 Download Manager Plugin up to 3.3.66 on WordPress. It has been rated as problematic. Impacted is the function wp_kses_post of the component Shortcode Handler. Performing a manipulation of the argument icon results in cross site scripting.

This vulnerability was named CVE-2026-16685. The attack may be initiated remotely. There is no available exploit.