cleantalk
Vulnerabilities and Security Researches

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy), CVE-2022-0707

CVE, Research URL

CVE-2022-0707

Published on
Apr 18, 2022
Research Description
The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack
Affected versions
max 2.11.6.
Status
vulnerable