Easy Digital Downloads
Easy Digital Downloads adds tools for selling, managing, and delivering digital products and downloadable files through WordPress.
Easy Digital Downloads (easy-digital-downloads) is a WordPress plugin with 68 published CVE records in this archive. The latest tracked vulnerability was published Jul 29, 2026; the highest published CVSS base score is 9.8.
easy-digital-downloadsCVE-2026-12476: Easy Digital Downloads import upload permits Shop Manager arbitrary file upload
Easy Digital Downloads through 3.6.9 permits arbitrary file upload through the AJAX import-file path handled by edd_do_ajax_import_file_upload() on the edd_upload_import_file hook. A logged-in Shop Manager or higher-privileged user who can import supplies the edd-import-file upload; validation trusts the client-supplied MIME type, sanitize_file_name() preserves the original extension, and move_uploaded_file() writes the file into wp-content/uploads/edd/exports/. An attacker can therefore place an arbitrary file in a web-accessible directory, potentially leading to remote code execution where the server executes the uploaded type. Version 3.6.9.1 forces the validated CSV extension and confines subsequent import paths to the exports directory.
| Safe version |
|
||
|---|---|---|---|
| Jul 29, 2026 |
CVE-2026-12476
Easy Digital Downloads import upload permits Shop Manager arbitrary file upload
Easy Digital Downloads through 3.6.9 permits arbitrary file upload through the AJAX import-file path handled by edd_do_ajax_import_file_upload() on the edd_upload_import_file hook. A logged-in Shop Manager or higher-privileged user who can import supplies the edd-import-file upload; validation trusts the client-supplied MIME type, sanitize_file_name() preserves the original extension, and move_uploaded_file() writes the file into wp-content/uploads/edd/exports/. An attacker can therefore place an arbitrary file in a web-accessible directory, potentially leading to remote code execution where the server executes the uploaded type. Version 3.6.9.1 forces the validated CSV extension and confines subsequent import paths to the exports directory.
|
3.6.9.1 |
CVE7.2
NVDPending
|
| Jul 27, 2026 |
CVE-2026-66476
Easy Digital Downloads permits administrator-controlled file deletion
Easy Digital Downloads through 3.6.9 lets an administrator supply a file target to an undisclosed deletion operation without adequate path confinement. The operation can delete a server file writable by PHP.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Jul 23, 2026 |
CVE-2026-59524
Easy Digital Downloads: Privilege escalation or authentication bypass
Easy Digital Downloads is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 3.6.7.
|
3.6.8 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39503
Easy Digital Downloads: Broken access control
Easy Digital Downloads is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 3.6.5.
|
3.6.6 |
CVE7.5
NVDPending
|
| May 28, 2026 |
CVE-2026-7533
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Cross-site request forgery
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 3.6.7.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 31, 2025 |
CVE-2025-14783
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 06, 2025 |
CVE-2025-11271
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 20, 2025 |
CVE-2025-8102
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| May 29, 2025 |
CVE-2025-4670
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Cross-site scripting
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 25, 2025 |
CVE-2025-2252
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Sensitive information exposure
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 18, 2025 |
CVE-2024-13517
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Cross-site scripting
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD4.0
|
| Dec 21, 2024 |
CVE-2024-12875
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Filesystem traversal
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by filesystem traversal. Exploitation requires an authenticated administrator account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Dec 17, 2024 |
CVE-2024-9654
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE3.7
NVDPending
|
| Dec 13, 2024 |
CVE-2023-40005
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD9.8
|
| Nov 01, 2024 |
CVE-2024-43162
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Sep 24, 2024 |
CVE-2022-2439
Easy Digital Downloads – Simple eCommerce for Selling Digital Files: Code execution
Easy Digital Downloads – Simple eCommerce for Selling Digital Files is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Aug 29, 2024 |
CVE-2024-5057
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVD9.8
|
| Aug 12, 2024 |
CVE-2024-6692
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.3
NVD3.1
|
| Aug 12, 2024 |
CVE-2024-6691
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD4.0
|
| May 14, 2024 |
CVE-2024-32100
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| May 14, 2024 |
CVE-2024-31113
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 12, 2024 |
CVE-2024-31293
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 09, 2024 |
CVE-2024-2302
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy): Sensitive information exposure
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 05, 2024 |
CVE-2024-0659
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVD4.8
|
| Feb 01, 2024 |
CVE-2023-51684
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| May 02, 2023 |
CVE-2023-30869
Easy Digital Downloads: Privilege escalation or authentication bypass
Easy Digital Downloads is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Feb 21, 2023 |
CVE-2023-0380
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jan 20, 2023 |
CVE-2023-23489
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Nov 21, 2022 |
CVE-2022-3600
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Nov 07, 2022 |
CVE-2022-2387
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Aug 22, 2022 |
CVE-2022-33900
Easy Digital Downloads: Code execution
Easy Digital Downloads is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE4.1
NVD7.2
|
| Apr 18, 2022 |
CVE-2022-0707
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD4.3
|
| Apr 18, 2022 |
CVE-2022-0706
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Oct 21, 2021 |
CVE-2021-39354
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Oct 23, 2019 |
CVE-2015-9524
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9523
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9522
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9521
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9520
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9519
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9518
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9517
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9516
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9515
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9514
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9513
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9512
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9511
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9510
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9509
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9508
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9507
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9506
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9505
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9536
Easy Digital Downloads (EDD) Twenty-Twelve: Cross-site scripting
Easy Digital Downloads (EDD) Twenty-Twelve is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9535
Easy Digital Downloads (EDD) Shoppette: Cross-site scripting
Easy Digital Downloads (EDD) Shoppette is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9534
Easy Digital Downloads (EDD) Quota: Cross-site scripting
Easy Digital Downloads (EDD) Quota is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9533
Easy Digital Downloads (EDD) Lattice: Cross-site scripting
Easy Digital Downloads (EDD) Lattice is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9532
Easy Digital Downloads (EDD) Digital Store: Cross-site scripting
Easy Digital Downloads (EDD) Digital Store is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9531
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9530
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9529
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9528
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9527
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9526
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9525
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Aug 16, 2019 |
CVE-2019-15116
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Aug 16, 2019 |
CVE-2015-9324
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD9.8
|