← WordPress Vulnerabilities
WordPress security by component

Easy Digital Downloads

Easy Digital Downloads is a WordPress component with 66 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: easy-digital-downloads

CVE-2026-59524: Easy Digital Downloads: A security weakness

Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.7.

PublishedJul 23, 2026
Known safe version3.6.8
Safe version
Jul 23, 2026 CVE-2026-59524
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.7.
3.6.8
CVE6.5
NVDPending
Jun 15, 2026 CVE-2026-39503
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.5.
3.6.6
CVE7.5
NVDPending
May 28, 2026 CVE-2026-7533
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Cross-site request forgery
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 3.6.7.
> 3.6.7
CVE4.3
NVDPending
Dec 31, 2025 CVE-2025-14783
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Nov 06, 2025 CVE-2025-11271
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Aug 20, 2025 CVE-2025-8102
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
May 29, 2025 CVE-2025-4670
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Cross-site scripting
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 25, 2025 CVE-2025-2252
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Sensitive information exposure
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Jan 18, 2025 CVE-2024-13517
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Cross-site scripting
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.0
Dec 21, 2024 CVE-2024-12875
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Filesystem traversal
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVDPending
Dec 17, 2024 CVE-2024-9654
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.7
NVDPending
Dec 13, 2024 CVE-2023-40005
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD9.8
Nov 01, 2024 CVE-2024-43162
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Sep 24, 2024 CVE-2022-2439
Easy Digital Downloads – Simple eCommerce for Selling Digital Files: Code execution
Easy Digital Downloads – Simple eCommerce for Selling Digital Files is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVD7.2
Aug 29, 2024 CVE-2024-5057
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVD9.8
Aug 12, 2024 CVE-2024-6692
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.3
NVD3.1
Aug 12, 2024 CVE-2024-6691
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.0
May 14, 2024 CVE-2024-32100
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD7.5
May 14, 2024 CVE-2024-31113
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 12, 2024 CVE-2024-31293
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 09, 2024 CVE-2024-2302
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy): Sensitive information exposure
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Feb 05, 2024 CVE-2024-0659
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
Feb 01, 2024 CVE-2023-51684
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
May 02, 2023 CVE-2023-30869
Easy Digital Downloads: Privilege escalation or authentication bypass
Easy Digital Downloads is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
Feb 21, 2023 CVE-2023-0380
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jan 20, 2023 CVE-2023-23489
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Nov 21, 2022 CVE-2022-3600
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Nov 07, 2022 CVE-2022-2387
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Aug 22, 2022 CVE-2022-33900
Easy Digital Downloads: Code execution
Easy Digital Downloads is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE4.1
NVD7.2
Apr 18, 2022 CVE-2022-0707
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Apr 18, 2022 CVE-2022-0706
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Oct 21, 2021 CVE-2021-39354
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Oct 23, 2019 CVE-2015-9524
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9523
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9522
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9521
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9520
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9519
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9518
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9517
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9516
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9515
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9514
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9513
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9512
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9511
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9510
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9509
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9508
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9507
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9506
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9505
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9536
Easy Digital Downloads (EDD) Twenty-Twelve: Cross-site scripting
Easy Digital Downloads (EDD) Twenty-Twelve is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9535
Easy Digital Downloads (EDD) Shoppette: Cross-site scripting
Easy Digital Downloads (EDD) Shoppette is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9534
Easy Digital Downloads (EDD) Quota: Cross-site scripting
Easy Digital Downloads (EDD) Quota is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9533
Easy Digital Downloads (EDD) Lattice: Cross-site scripting
Easy Digital Downloads (EDD) Lattice is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9532
Easy Digital Downloads (EDD) Digital Store: Cross-site scripting
Easy Digital Downloads (EDD) Digital Store is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9531
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9530
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9529
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9528
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9527
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9526
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 23, 2019 CVE-2015-9525
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 16, 2019 CVE-2019-15116
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 16, 2019 CVE-2015-9324
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8