Input validation vulnerability in Easy Digital Downloads – Recent Purchases 1.0.2

A plugin called “Easy Digital Downloads – Recent Purchases” for WordPress has a security issue where hackers can access and run files from external servers without being authenticated. This can lead to bypassing security measures, accessing private information, or executing code. This can only happen if the setting “allow_url_include” is turned on.

Detected in:

Easy Digital Downloads – Recent Purchases open vulnerable versions: >= * <= 1.0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.