WordPress security by component
Easy Digital Downloads
Plugin description
Easy Digital Downloads is a WordPress component with 66 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
easy-digital-downloadsLatest vulnerability
CVE-2026-59524: Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.7.
| Safe version |
|
||
|---|---|---|---|
| Jul 23, 2026 |
CVE-2026-59524
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.7.
|
3.6.8 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39503
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.5.
|
3.6.6 |
CVE7.5
NVDPending
|
| May 28, 2026 |
CVE-2026-7533
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Cross-site request forgery
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 3.6.7.
|
> 3.6.7 |
CVE4.3
NVDPending
|
| Dec 31, 2025 |
CVE-2025-14783
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 06, 2025 |
CVE-2025-11271
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 20, 2025 |
CVE-2025-8102
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| May 29, 2025 |
CVE-2025-4670
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Cross-site scripting
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 25, 2025 |
CVE-2025-2252
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Sensitive information exposure
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 18, 2025 |
CVE-2024-13517
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Cross-site scripting
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD4.0
|
| Dec 21, 2024 |
CVE-2024-12875
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: Filesystem traversal
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Dec 17, 2024 |
CVE-2024-9654
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE3.7
NVDPending
|
| Dec 13, 2024 |
CVE-2023-40005
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD9.8
|
| Nov 01, 2024 |
CVE-2024-43162
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Sep 24, 2024 |
CVE-2022-2439
Easy Digital Downloads – Simple eCommerce for Selling Digital Files: Code execution
Easy Digital Downloads – Simple eCommerce for Selling Digital Files is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Aug 29, 2024 |
CVE-2024-5057
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVD9.8
|
| Aug 12, 2024 |
CVE-2024-6692
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.3
NVD3.1
|
| Aug 12, 2024 |
CVE-2024-6691
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD4.0
|
| May 14, 2024 |
CVE-2024-32100
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| May 14, 2024 |
CVE-2024-31113
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 12, 2024 |
CVE-2024-31293
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 09, 2024 |
CVE-2024-2302
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy): Sensitive information exposure
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 05, 2024 |
CVE-2024-0659
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVD4.8
|
| Feb 01, 2024 |
CVE-2023-51684
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): Cross-site scripting
Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| May 02, 2023 |
CVE-2023-30869
Easy Digital Downloads: Privilege escalation or authentication bypass
Easy Digital Downloads is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Feb 21, 2023 |
CVE-2023-0380
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jan 20, 2023 |
CVE-2023-23489
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Nov 21, 2022 |
CVE-2022-3600
Easy Digital Downloads: A security weakness
Easy Digital Downloads is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Nov 07, 2022 |
CVE-2022-2387
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Aug 22, 2022 |
CVE-2022-33900
Easy Digital Downloads: Code execution
Easy Digital Downloads is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE4.1
NVD7.2
|
| Apr 18, 2022 |
CVE-2022-0707
Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 18, 2022 |
CVE-2022-0706
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Oct 21, 2021 |
CVE-2021-39354
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Oct 23, 2019 |
CVE-2015-9524
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9523
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9522
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9521
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9520
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9519
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9518
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9517
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9516
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9515
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9514
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9513
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9512
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9511
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9510
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9509
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9508
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9507
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9506
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9505
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9536
Easy Digital Downloads (EDD) Twenty-Twelve: Cross-site scripting
Easy Digital Downloads (EDD) Twenty-Twelve is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9535
Easy Digital Downloads (EDD) Shoppette: Cross-site scripting
Easy Digital Downloads (EDD) Shoppette is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9534
Easy Digital Downloads (EDD) Quota: Cross-site scripting
Easy Digital Downloads (EDD) Quota is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9533
Easy Digital Downloads (EDD) Lattice: Cross-site scripting
Easy Digital Downloads (EDD) Lattice is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9532
Easy Digital Downloads (EDD) Digital Store: Cross-site scripting
Easy Digital Downloads (EDD) Digital Store is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9531
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9530
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9529
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9528
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9527
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9526
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 23, 2019 |
CVE-2015-9525
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 16, 2019 |
CVE-2019-15116
Easy Digital Downloads: Cross-site scripting
Easy Digital Downloads is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 16, 2019 |
CVE-2015-9324
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|