Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105194 | 1 Wordpress-extensions | 1 Easy Digital Downloads | 2026-10-09 | 4.3 Medium |
| The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase. | ||||
| CVE-2026-105190 | 1 Wordpress-extensions | 1 Easy Digital Downloads | 2026-10-09 | 5.3 Medium |
| The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role. | ||||
| CVE-2026-42638 | 2 Syed Balkhi, Wordpress-extensions | 2 Easy Digital Downloads, Easy Digital Downloads | 2026-10-07 | 7.5 High |
| Missing Authorization vulnerability in Awesomemotive Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.7.1. | ||||
Page 1 of 1.