Easy Digital Downloads: Cross-site request forgery
Easy Digital Downloads is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
- Component
- Easy Digital Downloads
- Plugin slug
easy-digital-downloads- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Aug 20, 2025
This CVE was published Aug 20, 2025 and is one of 66 known issues for this plugin.
Patch or disable the affected component.
Update Easy Digital Downloads to a release outside the affected range, or disable and remove it until a fixed version is available.
Technical description
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and edd_sendwp_remote_install() functions. This makes it possible for unauthenticated attackers to deactivate or download and activate the SendWP plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L