Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.5 - Missing Authorization
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
Minimum safe version
3.6.6
Update to 3.6.6 or later to address 75 fixable vulnerabilities
CVE-2025-14783
CVE-2025-11271
Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions
Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure
CVE-2024-13517
CVE-2024-12875
Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass
CVE-2022-2439
CVE-2024-43162
WordPress Easy Digital Downloads Plugin <= 3.3.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-6691
CVE-2024-5057
CVE-2024-32100
CVE-2024-31113
CVE-2024-31293
CVE-2024-2302
CVE-2024-0659
WordPress Easy Digital Downloads Plugin <= 3.1.5 is vulnerable to Broken Access Control
WordPress Easy Digital Downloads Plugin <= 3.2.5 is vulnerable to Cross Site Scripting (XSS)
Easy Digital Downloads <= 3.1.1.4.2 - Cross-Site Request Forgery via edd_trigger_upgrades
WordPress Easy Digital Downloads Plugin <= 3.1.1.4.2 is vulnerable to Cross Site Request Forgery (CSRF)
Easy Digital Downloads 3.1 - 3.1.1.4.1 - Unauthenticated Arbitrary Password Reset to Privilege Escalation
CVE-2023-30869
CVE-2023-0380
CVE-2023-23489
Easy Digital Downloads <= 2.5.7 - PHP Object Injection
Easy Digital Downloads < 2.5.8 - PHP Object Injection
Easy Digital Downloads < 2.10.3 - Unauthorised Stripe Disconnect via CSRF
Easy Digital Downloads <= 2.10.2 - Cross-Site Request Forgery
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.10.2 - Cross-Site Request Forgery
Easy Digital Downloads <= 2.10.3 - Reflected Cross-Site Scripting
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.11.2 - Reflected Cross-Site Scripting
CVE-2022-3600
CVE-2022-2387
CVE-2022-33900
WordPress Easy Digital Downloads Plugin <= 2.5.7 - PHP Object Injection
WordPress Easy Digital Downloads plugin <= 2.7.11 - Information Disclosure Vulnerability
WordPress Easy Digital Downloads plugin <= 2.9.15 - Stored Cross-Site Scripting (XSS) vulnerability
WordPress Easy Digital Downloads plugin <= 2.10.2 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-0706
CVE-2022-0707
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.3.2 - SQL Injection
CVE-2019-15116
CVE-2015-9536
CVE-2015-9532
CVE-2015-9525
CVE-2015-9534
CVE-2015-9529
CVE-2015-9527
CVE-2015-9523
CVE-2015-9524
CVE-2015-9521
CVE-2015-9522
CVE-2015-9514
CVE-2015-9520
CVE-2015-9519
CVE-2015-9535
CVE-2015-9516
CVE-2015-9533
CVE-2015-9515
CVE-2015-9531
CVE-2015-9530
CVE-2015-9513
CVE-2015-9528
CVE-2015-9512
CVE-2015-9526
CVE-2015-9505
CVE-2015-9511
CVE-2015-9510
CVE-2015-9509
CVE-2015-9508
CVE-2015-9507
CVE-2015-9506
CVE-2015-9518
CVE-2015-9517
CVE-2021-39354