cleantalk
Vulnerabilities and Security Researches

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy), CVE-2023-23489

CVE, Research URL

CVE-2023-23489

Published on
Jan 20, 2023
Research Description
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.
Affected versions
max 3.1.0.4.
Status
vulnerable