WordPress Download Manager plugin before 2.9.94 contains a cross-site scripting vulnerability via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
View the template here CVE-2019-15889.yaml
References:
https://www.cybersecurity-help.cz/vdb/SB2019041819