📦 Easy Digital Downloads

by Awesomemotive

🔍 What is Easy Digital Downloads?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-5057

CRITICAL CVSS 9.3 Aug 29, 2024

This SQL injection vulnerability in the Easy Digital Downloads WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects all WordPress sites running Easy Digital ...

CVE-2023-30869

CRITICAL CVSS 9.8 May 2, 2023

This vulnerability allows unauthenticated attackers to gain administrative privileges on WordPress sites running the Easy Digital Downloads plugin. Attackers can exploit improper authentication to esc...

CVE-2025-2252

MEDIUM CVSS 5.3 Mar 25, 2025

The Easy Digital Downloads WordPress plugin exposes private download post titles to unauthenticated users via an AJAX function. This affects all WordPress sites using the plugin up to version 3.3.6.1,...

CVE-2024-13517

MEDIUM CVSS 4.4 Jan 18, 2025

This stored XSS vulnerability in the Easy Digital Downloads WordPress plugin allows authenticated administrators to inject malicious scripts into page titles. The scripts execute when users view affec...

CVE-2024-12875

MEDIUM CVSS 4.9 Dec 21, 2024

This vulnerability allows authenticated WordPress administrators to perform directory traversal attacks through the file download functionality, enabling them to read arbitrary files on the server. Th...

CVE-2023-40005

MEDIUM CVSS 5.3 Dec 13, 2024

This CVE describes a Missing Authorization vulnerability in the Easy Digital Downloads WordPress plugin that allows attackers to exploit incorrectly configured access control security levels. It affec...

CVE-2024-43162

MEDIUM CVSS 4.3 Nov 1, 2024

This CVE describes a missing authorization vulnerability in the Easy Digital Downloads WordPress plugin that allows attackers to bypass access controls. It affects all versions up to 3.2.12, potential...

CVE-2024-6691

MEDIUM CVSS 4.4 Aug 12, 2024

This stored XSS vulnerability in the Easy Digital Downloads WordPress plugin allows authenticated administrators to inject malicious scripts that execute when users view affected pages. Only WordPress...