WordPress security changelog
CRITICAL
CVE-2023-23489
Modified
Easy Digital Downloads: SQL injection
Easy Digital Downloads is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
CVE / CNA score
9.8
CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score
9.8
CVSS 3.1 · nvd@nist.gov
- Component
- Easy Digital Downloads
- Plugin slug
easy-digital-downloads- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Jan 20, 2023
This CVE was published Jan 20, 2023 and is one of 66 known issues for this plugin.
What to do
Patch or disable the affected component.
Update Easy Digital Downloads to a release outside the affected range, or disable and remove it until a fixed version is available.
Source record
Technical description
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References