Vulnerabilities > Sandhillsdev > Easy Digital Downloads

DATE CVE VULNERABILITY TITLE RISK
2024-05-14 CVE-2024-32100 Unspecified vulnerability in Sandhillsdev Easy Digital Downloads
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.
network
low complexity
sandhillsdev
7.5
2024-05-14 CVE-2024-31113 Unspecified vulnerability in Sandhillsdev Easy Digital Downloads
Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.
network
low complexity
sandhillsdev
8.8
2024-04-12 CVE-2024-31293 Unspecified vulnerability in Sandhillsdev Easy Digital Downloads
Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6.
network
low complexity
sandhillsdev
8.8
2023-02-21 CVE-2023-0380 Unspecified vulnerability in Sandhillsdev Easy Digital Downloads
The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
network
low complexity
sandhillsdev
5.4
2023-01-20 CVE-2023-23489 SQL Injection vulnerability in Sandhillsdev Easy Digital Downloads
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.
network
low complexity
sandhillsdev CWE-89
critical
9.8