VendorsAwesome Motiveeasy_digital_downloadsall versions
Vulnerabilities

Awesome Motive Easy Digital Downloads

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

55CVEs
CVE-2015-9519
The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published 2019-10-23 · Modified
6.1EPSS 0.009
CVE-2015-9520
The Easy Digital Downloads (EDD) Per Product Emails extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published 2019-10-23 · Modified
6.1EPSS 0.009
CVE-2015-9521
The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published 2019-10-23 · Modified
6.1EPSS 0.009
CVE-2024-0659
Easy Digital Downloads <= 3.2.6 - Authenticated(Shop Manager+) Stored Cross-Site Scripting via variable pricing options
Published 2024-02-05 · Modified
5.5EPSS 0.004
CVE-2024-2302
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information Exposure
Published 2024-04-09 · Modified
5.3EPSS 0.006
CVE-2025-2252
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure
Published 2025-03-25 · Analyzed
5.3EPSS 0.004
CVE-2024-12875
Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Download
Published 2024-12-21 · Analyzed
4.9EPSS 0.010
CVE-2021-39354
Easy Digital Downloads <= 2.11.2 Authenticated Reflected Cross-Site Scripting
Published 2021-10-21 · Modified
4.8EPSS 0.009
CVE-2022-0706
Easy Digital Downloads < 2.11.6 - Admin+ Stored Cross-Site Scripting
Published 2022-04-18 · Modified
4.8EPSS 0.007
CVE-2024-6691
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Currency Settings
Published 2024-08-10 · Analyzed
4.4EPSS 0.004
CVE-2024-13517
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title
Published 2025-01-18 · Analyzed
4.4EPSS 0.002
CVE-2022-0707
Easy Digital Downloads < 2.11.6 - Arbitrary Payment Note Insertion via CSRF
Published 2022-04-18 · Modified
4.3EPSS 0.005
CVE-2022-2387
Easy Digital Downloads < 3.0 - Arbitrary Post Deletion via CSRF
Published 2022-11-07 · Modified
4.3EPSS 0.003
CVE-2024-9654
Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass
Published 2024-12-17 · Analyzed
3.7EPSS 0.004
CVE-2024-6692
Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text
Published 2024-08-10 · Analyzed
3.3EPSS 0.004
← Prev2 / 2