Input validation vulnerability in Easy Digital Downloads – eCommerce Payments and Subscriptions made easy 3.5.0

The Easy Digital Downloads plugin for WordPress has a security flaw that allows hackers to trick site administrators into deactivating or downloading and activating the SendWP plugin. This vulnerability affects all versions up to 3.5.0 and is caused by missing security checks in the plugin’s functions. This means that unauthenticated attackers can potentially gain access to a site and perform malicious actions if they can trick an administrator into clicking on a link.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.