Vulnerabilities > Awesomemotive > Easy Digital Downloads > 2.11.7

DATE CVE VULNERABILITY TITLE RISK
2022-11-21 CVE-2022-3600 Unspecified vulnerability in Awesomemotive Easy Digital Downloads
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.
network
low complexity
awesomemotive
critical
9.8
2022-11-07 CVE-2022-2387 Cross-Site Request Forgery (CSRF) vulnerability in Awesomemotive Easy Digital Downloads
The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history.
network
low complexity
awesomemotive CWE-352
4.3
2022-08-22 CVE-2022-33900 Deserialization of Untrusted Data vulnerability in Awesomemotive Easy Digital Downloads
PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.
network
low complexity
awesomemotive CWE-502
7.2