Extension WordPress

Vulnérabilités Easy Digital Downloads – eCommerce Payments and Subscriptions made easy, page 2

Cette page rassemble les failles publiées pour Easy Digital Downloads – eCommerce Payments and Subscriptions made easy, leurs plages de versions affectées et les correctifs signalés dans la base locale.

41Vulnérabilités
6Critiques
41Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

41 fiches

CVE-2023-51684 Moyenne · 6,4
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.2.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-3.2.5

Correctif

3.2.6

Publication

27/12/2023

Vulnérabilité Moyenne · 4,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.1.1.4.2 – Cross-Site Request Forgery via edd_trigger_upgrades

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1.4.2. This is due to missing or incorrect nonce validation on the edd_trigger_upgrades function. This makes it possible for…

Versions affectées

[*, 3.1.2)

Correctif

3.1.2

Publication

07/06/2023

CVE-2023-30869 Critique · 9,8
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads 3.1 – 3.1.1.4.1 – Unauthenticated Arbitrary Password Reset to Privilege Escalation

The Easy Digital Downloads plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege Escalation in versions 3.1 to 3.1.1.4.1. This is due to a lack of validation of a password reset key in the edd_validate_password_reset…

Versions affectées

[3.1, 3.1.1.4.2)

Correctif

3.1.1.4.2

Publication

02/05/2023

CVE-2023-0380 Moyenne · 6,4
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.1.0.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-3.1.0.4

Correctif

3.1.0.5

Publication

30/01/2023

CVE-2023-23489 Critique · 9,8
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads < 3.1.0.4 – SQL Injection

The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions before 3.1.0.4 via the 's' parameter used in the 'edd_download_search' AJAX action. This allows unauthenticated attackers to append additional SQL queries into already existing…

Versions affectées

*-3.1.0.3

Correctif

3.1.0.4

Publication

12/01/2023

CVE-2022-2387 Élevée · 8,8
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 2.11.7 – Cross-Site Request Forgery to Arbitrary Post Deletion

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.11.7 . This is due to missing or incorrect nonce validation when deleting payment history. Additionally, the plugin does…

Versions affectées

*-2.11.7

Correctif

3.0

Publication

17/10/2022

CVE-2022-3600 Élevée · 8,8
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 3.1.0.1.1 – Unauthenticated CSV Injection

The Easy Digital Downloads plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 3.1.0.1.1. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when…

Versions affectées

*-3.1.0.1.1

Correctif

3.1.0.2

Publication

28/09/2022

CVE-2022-0707 Élevée · 8,8
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 2.11.5 – Cross-Site Request Forgery

The Easy Digital Downloads WordPress plugin before version 2.11.6 does not have Cross-Site Request Forgery checks in place when inserting payment notes. This could allow attackers to make a logged admin insert arbitrary notes via a Cross-Site Request…

Versions affectées

[*, 2.11.6)

Correctif

2.11.6

Publication

09/04/2022

CVE-2022-0706 Moyenne · 5,5
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 2.11.5 – Admin+ Cross-Site Scripting

The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

Versions affectées

[*, 2.11.6)

Correctif

2.11.6

Publication

28/03/2022

CVE-2021-39354 Moyenne · 4,8
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 2.11.2 – Reflected Cross-Site Scripting

The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.

Versions affectées

*-2.11.2

Correctif

2.11.2.1

Publication

21/10/2021

Vulnérabilité Moyenne · 5,4
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.11.2 – Reflected Cross-Site Scripting

The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start-date' and 'end-date' parameters in versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.11.2

Correctif

2.11.2.1

Publication

19/10/2021

Vulnérabilité Moyenne · 6,1
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 2.10.3 – Reflected Cross-Site Scripting

The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-2.10.3

Correctif

2.10.4

Publication

04/05/2021

Vulnérabilité Moyenne · 4,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.10.2 – Cross-Site Request Forgery

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.2. This is due to missing or incorrect nonce validation on the edds_stripe_connect_process_disconnect() function. This makes it possible for…

Versions affectées

*-2.10.2

Correctif

2.10.3

Publication

16/04/2021

Vulnérabilité Moyenne · 4,3
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 2.10.2 – Cross-Site Request Forgery

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.2. This is due to missing or incorrect nonce validation on the edds_stripe_connect_process_disconnect function. This makes it possible for…

Versions affectées

[*, 2.10.3)

Correctif

2.10.3

Publication

14/04/2021

Vulnérabilité Critique · 9,8
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads <= 2.5.7 – PHP Object Injection

The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.7 via deserialization of untrusted input from cookies and request parameters. This allows unauthenticated attackers to inject a PHP…

Versions affectées

*-2.5.7

Correctif

2.5.8

Publication

02/03/2016

CVE-2015-9505 Moyenne · 6,1
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.3.6 – Cross-Site Scripting

The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused.

Versions affectées

[*, 1.8.7), [1.9, 1.9.10), [2.0, 2.0.5), [2.1, 2.1.11), [2.2, 2.2.9), [2.3, 2.3.7)

Correctif

1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, 2.3.7

Publication

20/04/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités