Extension WordPress
Vulnérabilités Easy Digital Downloads – eCommerce Payments and Subscriptions made easy, page 2
Cette page rassemble les failles publiées pour Easy Digital Downloads – eCommerce Payments and Subscriptions made easy, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
41 fiches
Easy Digital Downloads <= 3.2.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-3.2.5
3.2.6
27/12/2023
Easy Digital Downloads <= 3.1.5 – Missing Authorization
The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…
*-3.1.5
3.2.0
26/12/2023
Easy Digital Downloads <= 3.1.1.4.2 – Cross-Site Request Forgery via edd_trigger_upgrades
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1.4.2. This is due to missing or incorrect nonce validation on the edd_trigger_upgrades function. This makes it possible for…
[*, 3.1.2)
3.1.2
07/06/2023
Easy Digital Downloads 3.1 – 3.1.1.4.1 – Unauthenticated Arbitrary Password Reset to Privilege Escalation
The Easy Digital Downloads plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege Escalation in versions 3.1 to 3.1.1.4.1. This is due to a lack of validation of a password reset key in the edd_validate_password_reset…
[3.1, 3.1.1.4.2)
3.1.1.4.2
02/05/2023
Easy Digital Downloads <= 3.1.0.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-3.1.0.4
3.1.0.5
30/01/2023
Easy Digital Downloads < 3.1.0.4 – SQL Injection
The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions before 3.1.0.4 via the 's' parameter used in the 'edd_download_search' AJAX action. This allows unauthenticated attackers to append additional SQL queries into already existing…
*-3.1.0.3
3.1.0.4
12/01/2023
Easy Digital Downloads <= 2.11.7 – Cross-Site Request Forgery to Arbitrary Post Deletion
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.11.7 . This is due to missing or incorrect nonce validation when deleting payment history. Additionally, the plugin does…
*-2.11.7
3.0
17/10/2022
Easy Digital Downloads <= 3.1.0.1.1 – Unauthenticated CSV Injection
The Easy Digital Downloads plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 3.1.0.1.1. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when…
*-3.1.0.1.1
3.1.0.2
28/09/2022
Easy Digital Downloads <= 3.0.1 – PHP Object Injection
The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object.
*-3.0.1
3.0.2
10/08/2022
Easy Digital Downloads <= 2.11.5 – Cross-Site Request Forgery
The Easy Digital Downloads WordPress plugin before version 2.11.6 does not have Cross-Site Request Forgery checks in place when inserting payment notes. This could allow attackers to make a logged admin insert arbitrary notes via a Cross-Site Request…
[*, 2.11.6)
2.11.6
09/04/2022
Easy Digital Downloads <= 2.11.5 – Admin+ Cross-Site Scripting
The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
[*, 2.11.6)
2.11.6
28/03/2022
Easy Digital Downloads <= 2.11.2 – Reflected Cross-Site Scripting
The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.
*-2.11.2
2.11.2.1
21/10/2021
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.11.2 – Reflected Cross-Site Scripting
The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start-date' and 'end-date' parameters in versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping. This makes it possible…
*-2.11.2
2.11.2.1
19/10/2021
Easy Digital Downloads <= 2.10.3 – Reflected Cross-Site Scripting
The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-2.10.3
2.10.4
04/05/2021
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.10.2 – Cross-Site Request Forgery
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.2. This is due to missing or incorrect nonce validation on the edds_stripe_connect_process_disconnect() function. This makes it possible for…
*-2.10.2
2.10.3
16/04/2021
Easy Digital Downloads <= 2.10.2 – Cross-Site Request Forgery
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.2. This is due to missing or incorrect nonce validation on the edds_stripe_connect_process_disconnect function. This makes it possible for…
[*, 2.10.3)
2.10.3
14/04/2021
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.3.2 – SQL Injection
The Easy Digital Downloads – Simple Ecommerce for Selling Digital Files WordPress plugin was affected by a SQL Injection security vulnerability. Versions up to, and including, 2.3.2 were affected.
*-2.3.2
2.3.3
22/09/2020
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.9.15 – Stored Cross-Site Scripting
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
[*, 2.9.16)
2.9.16
12/06/2019
Easy Digital Downloads <= 2.5.7 – PHP Object Injection
The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.7 via deserialization of untrusted input from cookies and request parameters. This allows unauthenticated attackers to inject a PHP…
*-2.5.7
2.5.8
02/03/2016
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.3.6 – Cross-Site Scripting
The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused.
[*, 1.8.7), [1.9, 1.9.10), [2.0, 2.0.5), [2.1, 2.1.11), [2.2, 2.2.9), [2.3, 2.3.7)
1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, 2.3.7
20/04/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.