VendorsSandhillsdeveasy_digital_downloadsall versions
Vulnerabilities

Sandhillsdev Sandhills Development Easy Digital Downloads

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-23489
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.
Published 2023-01-20 · Modified
9.8EPSS 0.112
CVE-2024-31293
WordPress Easy Digital Downloads plugin <= 3.2.6 - Cross Site Request Forgery (CSRF) vulnerability
Published 2024-04-12 · Modified
8.8EPSS 0.002
CVE-2024-31113
WordPress Easy Digital Downloads plugin <= 3.2.11 - Cross Site Request Forgery (CSRF) vulnerability
Published 2024-05-10 · Modified
8.8EPSS 0.002
CVE-2024-32100
WordPress Easy Digital Downloads plugin <= 3.2.11 - Sensitive Data Exposure vulnerability
Published 2024-05-13 · Modified
7.5EPSS 0.006
CVE-2023-0380
Easy Digital Downloads < 3.1.0.5 - Contributor+ Stored XSS
Published 2023-02-21 · Modified
5.4EPSS 0.005