Easydigitaldownloads
Easydigitaldownloads Easy Digital Downloads: vulnerabilidades y CVE
Easydigitaldownloads Easy Digital Downloads tiene 10 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses9
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42638 | Alta (7.5) | 0.26% | — | 6 oct 2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions. |
| CVE-2026-95522 | Alta (7.6) | 0.29% | — | 23 sept 2026 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. |
| CVE-2026-12476 | Alta (7.2) | 1.2% | — | 29 jul 2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload()… |
| CVE-2026-66476 | Media (4.9) | 0.50% | — | 27 jul 2026 | Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. |
| CVE-2026-59524 | Media (6.5) | 0.42% | — | 23 jul 2026 | Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. |
| CVE-2026-39503 | Alta (7.5) | 0.35% | — | 15 jun 2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions. |
| CVE-2026-7533 | Media (4.3) | 0.20% | — | 28 may 2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()`… |
| CVE-2025-14783 | Media (4.3) | 0.35% | — | 31 dic 2025 | The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the… |
| CVE-2025-11271 | Media (5.3) | 0.30% | — | 6 nov 2025 | The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the… |
| CVE-2025-8102 | Media (5.4) | 0.16% | — | 20 ago 2025 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.