plugin

Edd Upload File Vulnerabilities

2 known security issues reported for the Edd Upload File WordPress plugin. Most recent disclosed Oct 23, 2019.

1 critical

Running Edd Upload File on your site? Check whether your installed version is affected.

Scan your site free

Easy Digital Downloads – Upload File [edd-upload-file] < 1.0.4

unknown

[en] The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Oct 23, 2019

CVE-2015-9530 on NVD →

Easy Digital Downloads – Upload File <= 1.0.4 - Arbitrary File Upload/Deletion

critical

The Easy Digital Downloads – Upload File for WordPress is vulnerable to Arbitrary File Upload/Delete and Remote Code Execution via the 'edd_upload_file_delete', 'edd_upload_file_view_files', and 'create_upload_dir' functions in versions up to, and including, 1.0.4. This makes it possible for authenticated attackers to...

CVSS:
9.8
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Apr 9, 2015

CVE-2015-9530 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database