Extension WordPress

Vulnérabilités Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Cette page rassemble les failles publiées pour Easy Digital Downloads – eCommerce Payments and Subscriptions made easy, leurs plages de versions affectées et les correctifs signalés dans la base locale.

41Vulnérabilités
6Critiques
41Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

41 fiches

CVE-2026-7533 Moyenne · 4,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.6.7 – Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init`…

Versions affectées

*-3.6.7

Correctif

3.6.8

Publication

27/05/2026

CVE-2026-39503 Moyenne · 5,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.5 – Missing Authorization

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.6.5. This makes it…

Versions affectées

*-3.6.5

Correctif

3.6.6

Publication

20/04/2026

CVE-2025-14783 Moyenne · 4,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.6.2 – Unvalidated Redirect in Password Reset Flow via edd_redirect

The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it…

Versions affectées

*-3.6.2

Correctif

3.6.3

Publication

30/12/2025

CVE-2025-11271 Moyenne · 5,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Download <= 3.5.2 – Insufficient Verification to Order Manipulation

The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. Because…

Versions affectées

*-3.5.2

Correctif

3.5.3

Publication

05/11/2025

CVE-2025-8102 Moyenne · 5,4
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.5.0 – Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and edd_sendwp_remote_install() functions. This makes it possible…

Versions affectées

*-3.5.0

Correctif

3.5.1

Publication

20/08/2025

CVE-2025-4670 Moyenne · 6,4
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.3.8.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization…

Versions affectées

*-3.3.8.1

Correctif

3.3.9

Publication

28/05/2025

CVE-2025-2252 Moyenne · 5,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 – Unauthenticated Private Post Title Disclosure

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated…

Versions affectées

*-3.3.6.1

Correctif

3.3.7

Publication

24/03/2025

CVE-2024-13517 Moyenne · 4,4
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 – Authenticated (Admin+) Stored Cross-Site Scripting via Title

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and…

Versions affectées

*-3.3.2

Correctif

3.3.3

Publication

17/01/2025

CVE-2024-12875 Moyenne · 4,9
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.3.2 – Authenticated (Admin+) Arbitrary File Download

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. This makes it possible for authenticated…

Versions affectées

*-3.3.2

Correctif

3.3.3

Publication

20/12/2024

CVE-2024-9654 Faible · 3,7
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads 3.1 – 3.3.4 – Improper Authorization to Paywall Bypass

The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the…

Versions affectées

3.1-3.3.4

Correctif

3.3.5

Publication

16/12/2024

CVE-2022-2439 Élevée · 7,2
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 – Authenticated (Admin+) PHAR Deserialization

The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, and including 3.3.3. This makes it possible for authenticated…

Versions affectées

*-3.3.3

Correctif

3.3.4

Publication

23/09/2024

CVE-2024-6692 Faible · 3,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 – Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Agreement Text value in all versions up to, and including, 3.3.2…

Versions affectées

*-3.3.2

Correctif

3.3.3

Publication

09/08/2024

CVE-2024-6691 Moyenne · 4,4
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 – Authenticated (Admin+) Stored Cross-Site Scripting via Currency Settings

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the currency value in all versions up to, and including, 3.3.2 due…

Versions affectées

*-3.3.2

Correctif

3.3.3

Publication

09/08/2024

CVE-2024-43162 Moyenne · 4,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.2.12 – Missing Authorization

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.12. This makes…

Versions affectées

*-3.2.12

Correctif

3.3.1

Publication

07/08/2024

CVE-2024-5057 Critique · 10,0
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.2.12 – Unauthenticated SQL Injection

The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-3.2.12

Correctif

3.3.1

Publication

01/08/2024

CVE-2024-31113 Moyenne · 4,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.2.11 – Cross-Site Request Forgery

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.11. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible…

Versions affectées

*-3.2.11

Correctif

3.2.12

Publication

09/05/2024

CVE-2024-32100 Moyenne · 5,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.2.11 – Unauthenticated Sensitive Information Exposure

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.11. This makes it possible for…

Versions affectées

*-3.2.11

Correctif

3.2.12

Publication

09/05/2024

CVE-2024-31293 Moyenne · 4,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.2.6 – Cross-Site Request Forgery

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated…

Versions affectées

*-3.2.6

Correctif

3.2.7

Publication

05/04/2024

CVE-2024-2302 Moyenne · 5,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 – Sensitive Information Exposure

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for…

Versions affectées

*-3.2.9

Correctif

3.2.10

Publication

03/04/2024

CVE-2024-0659 Moyenne · 5,5
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.2.6 – Authenticated(Shop Manager+) Stored Cross-Site Scripting via variable pricing options

The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due…

Versions affectées

*-3.2.6

Correctif

3.2.7

Publication

02/02/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités