plugin

Easy Digital Downloads Vulnerabilities

121 known security issues reported for the Easy Digital Downloads WordPress plugin. Most recent disclosed Jul 28, 2026.

6 critical 5 high 31 medium 2 low

Running Easy Digital Downloads on your site? Check whether your installed version is affected.

Scan your site free

Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter

high

The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header a...

CVSS:
7.2
Affected:
up to 3.6.9
Fixed in:
3.6.9.1
Disclosed:
Jul 28, 2026

CVE-2026-12476 on NVD →

Easy Digital Downloads <= 3.6.9 - Authenticated (Admin) Arbitrary File Deletion

medium

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.6.9. This makes it possible for authenticated attackers, with Administrator-level access and above, t...

CVSS:
6.5
Affected:
up to 3.6.9
Fixed in:
3.6.9.1
Disclosed:
Jul 27, 2026

CVE-2026-66476 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.7 - Missing Authorization

medium

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.6.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.6.7
Fixed in:
3.6.8
Disclosed:
Jul 22, 2026

CVE-2026-59524 on NVD →

Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens from a user-supplie...

CVSS:
4.3
Affected:
up to 3.6.7
Fixed in:
3.6.8
Disclosed:
May 27, 2026

CVE-2026-7533 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.5 - Missing Authorization

medium

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.6.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.6.5
Fixed in:
3.6.6
Disclosed:
Apr 20, 2026

CVE-2026-39503 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.3

unknown

[en] The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the pa...

Affected:
up to 3.6.3
Fixed in:
3.6.3
Disclosed:
Dec 31, 2025

CVE-2025-14783 on NVD →

Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the passwor...

CVSS:
4.3
Affected:
up to 3.6.2
Fixed in:
3.6.3
Disclosed:
Dec 30, 2025

CVE-2025-14783 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.5.3 (closed)

unknown

[en] The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. Because this value is attacker-supplied, an unauthent...

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Nov 6, 2025

CVE-2025-11271 on NVD →

Easy Digital Download <= 3.5.2 - Insufficient Verification to Order Manipulation

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. Because this value is attacker-supplied, an unauthenticate...

CVSS:
5.3
Affected:
up to 3.5.2
Fixed in:
3.5.3
Disclosed:
Nov 5, 2025

CVE-2025-11271 on NVD →

Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and edd_sendwp_remote_install() functions. This makes it possible for unauthenticated attackers to deactivate o...

CVSS:
5.4
Affected:
up to 3.5.0
Fixed in:
3.5.1
Disclosed:
Aug 19, 2025

CVE-2025-8102 on NVD →

Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode

medium

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This...

CVSS:
6.4
Affected:
up to 3.3.8.1
Fixed in:
3.3.9
Disclosed:
May 28, 2025

CVE-2025-4670 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure

medium

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated attackers to extract private post titl...

CVSS:
5.3
Affected:
up to 3.3.6.1
Fixed in:
3.3.7
Disclosed:
Mar 24, 2025

CVE-2025-2252 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 (closed)

unknown

[en] The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...

Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Jan 18, 2025

CVE-2024-13517 on NVD →

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title

medium

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

CVSS:
4.4
Affected:
up to 3.3.2
Fixed in:
3.3.3
Disclosed:
Jan 17, 2025

CVE-2024-13517 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 (closed)

unknown

[en] The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to re...

Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Dec 21, 2024

CVE-2024-12875 on NVD →

Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Download

medium

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to read th...

CVSS:
4.9
Affected:
up to 3.3.2
Fixed in:
3.3.3
Disclosed:
Dec 20, 2024

CVE-2024-12875 on NVD →

Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass

low

The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the intended recipient of the purchase receipt. This makes it possible fo...

CVSS:
3.7
Affected:
3.1 – 3.3.4
Fixed in:
3.3.5
Disclosed:
Dec 16, 2024

CVE-2024-9654 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.0 (closed)

unknown

[en] Missing Authorization vulnerability in Easy Digital Downloads Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.1.5.

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Dec 13, 2024

CVE-2023-40005 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.1 (closed)

unknown

[en] Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.2.12.

Affected:
up to 3.3.1
Fixed in:
3.3.1
Disclosed:
Nov 1, 2024

CVE-2024-43162 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.4 (closed)

unknown

[en] The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, and including 3.3.3. This makes it possible for authenticated administrative users to call files using a PHAR wrapper,...

Affected:
up to 3.3.4
Fixed in:
3.3.4
Disclosed:
Sep 24, 2024

CVE-2022-2439 on NVD →

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR Deserialization

high

The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, and including 3.3.3. This makes it possible for authenticated administrative users to call files using a PHAR wrapper, that...

CVSS:
7.2
Affected:
up to 3.3.3
Fixed in:
3.3.4
Disclosed:
Sep 23, 2024

CVE-2022-2439 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.1 (closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.

Affected:
up to 3.3.1
Fixed in:
3.3.1
Disclosed:
Aug 29, 2024

CVE-2024-5057 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 (closed)

unknown

[en] The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the currency value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possi...

Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Aug 10, 2024

CVE-2024-6691 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 (closed)

unknown

[en] The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Agreement Text value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it...

Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Aug 10, 2024

CVE-2024-6692 on NVD →

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Currency Settings

medium

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the currency value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible f...

CVSS:
4.4
Affected:
up to 3.3.2
Fixed in:
3.3.3
Disclosed:
Aug 9, 2024

CVE-2024-6691 on NVD →

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text

low

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Agreement Text value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it poss...

CVSS:
3.3
Affected:
up to 3.3.2
Fixed in:
3.3.3
Disclosed:
Aug 9, 2024

CVE-2024-6692 on NVD →

Easy Digital Downloads <= 3.2.12 - Missing Authorization

medium

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level access and above,...

CVSS:
4.3
Affected:
up to 3.2.12
Fixed in:
3.3.1
Disclosed:
Aug 7, 2024

CVE-2024-43162 on NVD →

Easy Digital Downloads <= 3.2.12 - Unauthenticated SQL Injection

critical

The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL...

CVSS:
10
Affected:
up to 3.2.12
Fixed in:
3.3.1
Disclosed:
Aug 1, 2024

CVE-2024-5057 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.12 (closed)

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.

Affected:
up to 3.2.12
Fixed in:
3.2.12
Disclosed:
May 13, 2024

CVE-2024-32100 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.12 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.

Affected:
up to 3.2.12
Fixed in:
3.2.12
Disclosed:
May 10, 2024

CVE-2024-31113 on NVD →

Easy Digital Downloads <= 3.2.11 - Unauthenticated Sensitive Information Exposure

medium

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.11. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.2.11
Fixed in:
3.2.12
Disclosed:
May 9, 2024

CVE-2024-32100 on NVD →

Easy Digital Downloads <= 3.2.11 - Cross-Site Request Forgery

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.11. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick...

CVSS:
4.3
Affected:
up to 3.2.11
Fixed in:
3.2.12
Disclosed:
May 9, 2024

CVE-2024-31113 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.7 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6.

Affected:
up to 3.2.7
Fixed in:
3.2.7
Disclosed:
Apr 12, 2024

CVE-2024-31293 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.10 (closed)

unknown

[en] The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listi...

Affected:
up to 3.2.10
Fixed in:
3.2.10
Disclosed:
Apr 9, 2024

CVE-2024-2302 on NVD →

Easy Digital Downloads <= 3.2.6 - Cross-Site Request Forgery

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted the...

CVSS:
4.3
Affected:
up to 3.2.6
Fixed in:
3.2.7
Disclosed:
Apr 5, 2024

CVE-2024-31293 on NVD →

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information Exposure

medium

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing. T...

CVSS:
5.3
Affected:
up to 3.2.9
Fixed in:
3.2.10
Disclosed:
Apr 3, 2024

CVE-2024-2302 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.7 (closed)

unknown

[en] The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possib...

Affected:
up to 3.2.7
Fixed in:
3.2.7
Disclosed:
Feb 5, 2024

CVE-2024-0659 on NVD →

Easy Digital Downloads <= 3.2.6 - Authenticated(Shop Manager+) Stored Cross-Site Scripting via variable pricing options

medium

The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible fo...

CVSS:
5.5
Affected:
up to 3.2.6
Fixed in:
3.2.7
Disclosed:
Feb 2, 2024

CVE-2024-0659 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.6 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Digital Downloads Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) allows Stored XSS.This issue affects Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payment...

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Feb 1, 2024

CVE-2023-51684 on NVD →

Easy Digital Downloads <= 3.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 3.2.5
Fixed in:
3.2.6
Disclosed:
Dec 27, 2023

CVE-2023-51684 on NVD →

Easy Digital Downloads <= 3.1.5 - Missing Authorization

medium

The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.5. This makes it possible for unauthenticated attackers to perform an unauthorized ac...

CVSS:
5.3
Affected:
up to 3.1.5
Fixed in:
3.2.0
Disclosed:
Dec 26, 2023

CVE-2023-40005 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.2 (closed)

unknown

Update the WordPress Easy Digital Downloads plugin to the latest available version (at least 3.1.2). An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Easy Digital Downloads Plugin. This could allow a malicious actor to force higher privileged users to execute u...

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jun 8, 2023

Easy Digital Downloads <= 3.1.1.4.2 - Cross-Site Request Forgery via edd_trigger_upgrades

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1.4.2. This is due to missing or incorrect nonce validation on the edd_trigger_upgrades function. This makes it possible for unauthenticated attackers to trigger plugin upgrades via a forged...

CVSS:
4.3
Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jun 7, 2023

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.2 (closed)

unknown

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1.4.2. This is due to missing or incorrect nonce validation on the edd_trigger_upgrades function. This makes it possible for unauthenticated attackers to trigger plugin upgrades via a forged...

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jun 7, 2023

Easy Digital Downloads 3.1 - 3.1.1.4.1 - Unauthenticated Arbitrary Password Reset to Privilege Escalation

critical

The Easy Digital Downloads plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege Escalation in versions 3.1 to 3.1.1.4.1. This is due to a lack of validation of a password reset key in the edd_validate_password_reset function. This makes it possible for unauthenticated attackers t...

CVSS:
9.8
Affected:
3.1 – 3.1.1.4.2
Fixed in:
3.1.1.4.2
Disclosed:
May 2, 2023

CVE-2023-30869 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] >= 3.1 - <= 3.1.1.4.1 (closed)

unknown

[en] Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.

Affected:
3.1 – 3.1.1.4.1
Fixed in:
3.1.1.4.1
Disclosed:
May 2, 2023

CVE-2023-30869 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] >= 3.1 - <= 3.1.1.4.1 (closed)

unknown

The Easy Digital Downloads plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege Escalation in versions 3.1 to 3.1.1.4.1. This is due to a lack of validation of a password reset key in the edd_validate_password_reset function. This makes it possible for unauthenticated attackers t...

Affected:
3.1 – 3.1.1.4.1
Fixed in:
3.1.1.4.1
Disclosed:
May 2, 2023

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.5 (closed)

unknown

[en] The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 3.1.0.5
Fixed in:
3.1.0.5
Disclosed:
Feb 21, 2023

CVE-2023-0380 on NVD →

Easy Digital Downloads <= 3.1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...

CVSS:
6.4
Affected:
up to 3.1.0.4
Fixed in:
3.1.0.5
Disclosed:
Jan 30, 2023

CVE-2023-0380 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.4 (closed)

unknown

[en] The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.

Affected:
up to 3.1.0.4
Fixed in:
3.1.0.4
Disclosed:
Jan 20, 2023

CVE-2023-23489 on NVD →

Easy Digital Downloads < 3.1.0.4 - SQL Injection

critical

The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions before 3.1.0.4 via the 's' parameter used in the 'edd_download_search' AJAX action. This allows unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive inform...

CVSS:
9.8
Affected:
up to 3.1.0.3
Fixed in:
3.1.0.4
Disclosed:
Jan 12, 2023

CVE-2023-23489 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.2 (closed)

unknown

[en] The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.

Affected:
up to 3.1.0.2
Fixed in:
3.1.0.2
Disclosed:
Nov 21, 2022

CVE-2022-3600 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.0 (closed)

unknown

[en] The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Nov 7, 2022

CVE-2022-2387 on NVD →

Easy Digital Downloads <= 2.11.7 - Cross-Site Request Forgery to Arbitrary Post Deletion

high

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.11.7 . This is due to missing or incorrect nonce validation when deleting payment history. Additionally, the plugin does not ensure that the item about to be deleted is payment history. This m...

CVSS:
8.8
Affected:
up to 2.11.7
Fixed in:
3.0
Disclosed:
Oct 17, 2022

CVE-2022-2387 on NVD →

Easy Digital Downloads <= 3.1.0.1.1 - Unauthenticated CSV Injection

high

The Easy Digital Downloads plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 3.1.0.1.1. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulne...

CVSS:
8.8
Affected:
up to 3.1.0.1.1
Fixed in:
3.1.0.2
Disclosed:
Sep 28, 2022

CVE-2022-3600 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.1.4.2 (closed)

unknown

[en] PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.

Affected:
up to 3.1.1.4.2
Fixed in:
3.1.1.4.2
Disclosed:
Aug 22, 2022

CVE-2022-33900 on NVD →

Easy Digital Downloads <= 3.0.1 - PHP Object Injection

critical

The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object.

CVSS:
9.8
Affected:
up to 3.0.1
Fixed in:
3.0.2
Disclosed:
Aug 10, 2022

CVE-2022-33900 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.11.6 (closed)

unknown

[en] The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack

Affected:
up to 2.11.6
Fixed in:
2.11.6
Disclosed:
Apr 18, 2022

CVE-2022-0707 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.11.6 (closed)

unknown

[en] The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

Affected:
up to 2.11.6
Fixed in:
2.11.6
Disclosed:
Apr 18, 2022

CVE-2022-0706 on NVD →

Easy Digital Downloads <= 2.11.5 - Cross-Site Request Forgery

high

The Easy Digital Downloads WordPress plugin before version 2.11.6 does not have Cross-Site Request Forgery checks in place when inserting payment notes. This could allow attackers to make a logged admin insert arbitrary notes via a Cross-Site Request Forgery attack.

CVSS:
8.8
Affected:
up to 2.11.6
Fixed in:
2.11.6
Disclosed:
Apr 9, 2022

CVE-2022-0707 on NVD →

Easy Digital Downloads <= 2.11.5 - Admin+ Cross-Site Scripting

medium

The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 2.11.6
Fixed in:
2.11.6
Disclosed:
Mar 28, 2022

CVE-2022-0706 on NVD →

Easy Digital Downloads <= 2.11.2 - Reflected Cross-Site Scripting

medium

The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.

CVSS:
4.8
Affected:
up to 2.11.2
Fixed in:
2.11.2.1
Disclosed:
Oct 21, 2021

CVE-2021-39354 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.11.2.1 (closed)

unknown

[en] The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.

Affected:
up to 2.11.2.1
Fixed in:
2.11.2.1
Disclosed:
Oct 21, 2021

CVE-2021-39354 on NVD →

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.11.2 - Reflected Cross-Site Scripting

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start-date' and 'end-date' parameters in versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web s...

CVSS:
5.4
Affected:
up to 2.11.2
Fixed in:
2.11.2.1
Disclosed:
Oct 19, 2021

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.11.2.1 (closed)

unknown

The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start-date' and 'end-date' parameters in versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web s...

Affected:
up to 2.11.2.1
Fixed in:
2.11.2.1
Disclosed:
Oct 19, 2021

Easy Digital Downloads <= 2.10.3 - Reflected Cross-Site Scripting

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 2.10.3
Fixed in:
2.10.4
Disclosed:
May 4, 2021

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.4 (closed)

unknown

The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 2.10.4
Fixed in:
2.10.4
Disclosed:
May 4, 2021

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.10.2 - Cross-Site Request Forgery

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.2. This is due to missing or incorrect nonce validation on the edds_stripe_connect_process_disconnect() function. This makes it possible for unauthenticated attackers to disconnect any user...

CVSS:
4.3
Affected:
up to 2.10.2
Fixed in:
2.10.3
Disclosed:
Apr 16, 2021

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.3 (closed)

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScan team in WordPress Easy Digital Downloads plugin (versions <= 2.10.2).

Affected:
up to 2.10.3
Fixed in:
2.10.3
Disclosed:
Apr 16, 2021

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.3 (closed)

unknown

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.2. This is due to missing or incorrect nonce validation on the edds_stripe_connect_process_disconnect() function. This makes it possible for unauthenticated attackers to disconnect any user...

Affected:
up to 2.10.3
Fixed in:
2.10.3
Disclosed:
Apr 16, 2021

Easy Digital Downloads <= 2.10.2 - Cross-Site Request Forgery

medium

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.2. This is due to missing or incorrect nonce validation on the edds_stripe_connect_process_disconnect function. This makes it possible for unauthenticated attackers to perform an unknown ac...

CVSS:
4.3
Affected:
up to 2.10.3
Fixed in:
2.10.3
Disclosed:
Apr 14, 2021

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.3 (closed)

unknown

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.2. This is due to missing or incorrect nonce validation on the edds_stripe_connect_process_disconnect function. This makes it possible for unauthenticated attackers to perform an unknown ac...

Affected:
up to 2.10.3
Fixed in:
2.10.3
Disclosed:
Apr 14, 2021

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.3.2 - SQL Injection

critical

The Easy Digital Downloads – Simple Ecommerce for Selling Digital Files WordPress plugin was affected by a SQL Injection security vulnerability. Versions up to, and including, 2.3.2 were affected.

CVSS:
9.8
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Sep 22, 2020

CVE-2015-9324 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Manual Purchases extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9517 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) PDF Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9518 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Amazon S3 extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9506 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9507 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Commissions extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9508 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Content Restriction extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9509 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Cross-sell Upsell extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9510 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Conditional Success Redirects extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9511 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9505 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9526 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) CSV Manager extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9512 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9528 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9513 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9530 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9531 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) htaccess Editor extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9515 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Lattice theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9533 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9516 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9535 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9519 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Per Product Emails extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9520 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Free Downloads extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9514 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) QR Code extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9522 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9521 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9524 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9523 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9527 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9529 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Quota theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9534 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9525 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9532 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 (closed)

unknown

[en] The Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Oct 23, 2019

CVE-2015-9536 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.9.16 (closed)

unknown

[en] The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.

Affected:
up to 2.9.16
Fixed in:
2.9.16
Disclosed:
Aug 16, 2019

CVE-2019-15116 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.3 (closed)

unknown

[en] The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.

Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
Aug 16, 2019

CVE-2015-9324 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.9.16 (closed)

unknown

Stored Cross-Site Scripting (XSS) vulnerability found in WordPress Easy Digital Downloads plugin (versions <= 2.9.15).

Affected:
up to 2.9.16
Fixed in:
2.9.16
Disclosed:
Jun 16, 2019

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.9.15 - Stored Cross-Site Scripting

medium

The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.

CVSS:
6.1
Affected:
up to 2.9.16
Fixed in:
2.9.16
Disclosed:
Jun 12, 2019

CVE-2019-15116 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.8 (closed)

unknown

WordPress Easy Digital Downloads plugin in 2.7.11 and earlier versions are vulnerable to information disclosure vulnerability. The plugin function edd_ajax_get_download_title is accessible to anyone logged in or logged out users. Update the plugin.

Affected:
up to 2.8
Fixed in:
2.8
Disclosed:
Mar 31, 2017

Easy Digital Downloads <= 2.5.7 - PHP Object Injection

critical

The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.7 via deserialization of untrusted input from cookies and request parameters. This allows unauthenticated attackers to inject a PHP Object.

CVSS:
9.8
Affected:
up to 2.5.7
Fixed in:
2.5.8
Disclosed:
Mar 2, 2016

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.5.8 (closed)

unknown

Because of this vulnerability, attackers can execute arbitrary PHP code. Upgrade the plugin.

Affected:
up to 2.5.8
Fixed in:
2.5.8
Disclosed:
Mar 2, 2016

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.5.8 (closed)

unknown

The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.7 via deserialization of untrusted input from cookies and request parameters. This allows unauthenticated attackers to inject a PHP Object.

Affected:
up to 2.5.8
Fixed in:
2.5.8
Disclosed:
Mar 2, 2016

Easy Digital Downloads (Various Versions) - Cross-Site Scripting

medium

The Easy Digital Downloads Plugin for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

CVSS:
6.1
Affected:
1.8 – 1.8.6, 1.9 – 1.9.9, 2.0 – 2.0.4, 2.1 – 2.1.10, 2.2 – 2.2.8, 2.3 – 2.3.6
Fixed in:
1.8.7
Disclosed:
Apr 20, 2015

CVE-2015-9512 on NVD →

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.3.6 - Cross-Site Scripting

medium

The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused.

CVSS:
6.1
Affected:
up to 1.8.7, 1.9 – 1.9.10, 2.0 – 2.0.5, 2.1 – 2.1.11, 2.2 – 2.2.9, 2.3 – 2.3.7
Fixed in:
1.8.7
Disclosed:
Apr 20, 2015

CVE-2015-9505 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.3 (closed)

unknown

The plugin did not property check for CSRF when disconnecting Stripe, allowing attackers to make logged in users with the manage_options capability disconnect the Stripe gateway via a CSRF attack.

Affected:
up to 2.10.3
Fixed in:
2.10.3

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.5.8 (closed)

unknown

Easy Digital Downloads unserializes user-submitted data from cookies and other request parameters, allowing for object injection.

Affected:
up to 2.5.8
Fixed in:
2.5.8

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] >= 3.1 - <= 3.3.4 (closed)

unknown
Affected:
3.1 – 3.3.4
Fixed in:
3.3.4

CVE-2024-9654 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.7 (closed)

unknown
Affected:
up to 3.3.7
Fixed in:
3.3.7

CVE-2025-2252 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.9 (closed)

unknown
Affected:
up to 3.3.9
Fixed in:
3.3.9

CVE-2025-4670 on NVD →

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.5.1 (closed)

unknown
Affected:
up to 3.5.1
Fixed in:
3.5.1

CVE-2025-8102 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database