Total vulnerabilities in the database
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.
No technical information available.
CWEs:
OWASP TOP 10: