Extension WordPress
Vulnérabilités Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
Cette page rassemble les failles publiées pour Easy Digital Downloads – eCommerce Payments and Subscriptions made easy, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
41 fiches
Easy Digital Downloads <= 3.6.7 – Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init`…
*-3.6.7
3.6.8
27/05/2026
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.5 – Missing Authorization
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.6.5. This makes it…
*-3.6.5
3.6.6
20/04/2026
Easy Digital Downloads <= 3.6.2 – Unvalidated Redirect in Password Reset Flow via edd_redirect
The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it…
*-3.6.2
3.6.3
30/12/2025
Easy Digital Download <= 3.5.2 – Insufficient Verification to Order Manipulation
The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. Because…
*-3.5.2
3.5.3
05/11/2025
Easy Digital Downloads <= 3.5.0 – Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and edd_sendwp_remote_install() functions. This makes it possible…
*-3.5.0
3.5.1
20/08/2025
Easy Digital Downloads <= 3.3.8.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization…
*-3.3.8.1
3.3.9
28/05/2025
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 – Unauthenticated Private Post Title Disclosure
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated…
*-3.3.6.1
3.3.7
24/03/2025
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 – Authenticated (Admin+) Stored Cross-Site Scripting via Title
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and…
*-3.3.2
3.3.3
17/01/2025
Easy Digital Downloads <= 3.3.2 – Authenticated (Admin+) Arbitrary File Download
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. This makes it possible for authenticated…
*-3.3.2
3.3.3
20/12/2024
Easy Digital Downloads 3.1 – 3.3.4 – Improper Authorization to Paywall Bypass
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the…
3.1-3.3.4
3.3.5
16/12/2024
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 – Authenticated (Admin+) PHAR Deserialization
The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, and including 3.3.3. This makes it possible for authenticated…
*-3.3.3
3.3.4
23/09/2024
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 – Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Agreement Text value in all versions up to, and including, 3.3.2…
*-3.3.2
3.3.3
09/08/2024
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 – Authenticated (Admin+) Stored Cross-Site Scripting via Currency Settings
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the currency value in all versions up to, and including, 3.3.2 due…
*-3.3.2
3.3.3
09/08/2024
Easy Digital Downloads <= 3.2.12 – Missing Authorization
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.12. This makes…
*-3.2.12
3.3.1
07/08/2024
Easy Digital Downloads <= 3.2.12 – Unauthenticated SQL Injection
The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-3.2.12
3.3.1
01/08/2024
Easy Digital Downloads <= 3.2.11 – Cross-Site Request Forgery
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.11. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible…
*-3.2.11
3.2.12
09/05/2024
Easy Digital Downloads <= 3.2.11 – Unauthenticated Sensitive Information Exposure
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.11. This makes it possible for…
*-3.2.11
3.2.12
09/05/2024
Easy Digital Downloads <= 3.2.6 – Cross-Site Request Forgery
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated…
*-3.2.6
3.2.7
05/04/2024
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 – Sensitive Information Exposure
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for…
*-3.2.9
3.2.10
03/04/2024
Easy Digital Downloads <= 3.2.6 – Authenticated(Shop Manager+) Stored Cross-Site Scripting via variable pricing options
The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due…
*-3.2.6
3.2.7
02/02/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.