CVE Tools

Easy Digital Downloads

65 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Easy Digital Downloads, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Easy Digital Downloads CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Easy Digital Downloads CVEs per month
MonthCVEs
2024-100
2024-111
2024-123
2025-011
2025-020
2025-031
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-061
2026-072
2026-080
2026-091

Severity

How the 65 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical69%
  • High35%
  • Medium5483%
  • Low23%

Latest CVEs

The 15 most recently published vulnerabilities affecting Easy Digital Downloads.

  1. CVE-2026-95522WordPress Easy Digital Downloads plugin <= 3.7.0 - SQL Injection vulnerability7.6
  2. CVE-2026-66476WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerability4.9
  3. CVE-2026-59524WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vulnerability6.5
  4. CVE-2026-39503WordPress Easy Digital Downloads plugin <= 3.6.5 - Broken Access Control vulnerability7.5
  5. CVE-2025-4670Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode6.4
  6. CVE-2025-2252Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure5.3
  7. CVE-2024-13517Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title4.4
  8. CVE-2024-12875Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Download4.9
  9. CVE-2024-9654Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass3.7
  10. CVE-2023-40005WordPress Easy Digital Downloads plugin <= 3.1.5 - Broken Access Control5.3
  11. CVE-2024-43162WordPress Easy Digital Downloads plugin <= 3.2.12 - Broken Access Control vulnerability4.3
  12. CVE-2022-2439Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR Deserialization7.2
  13. CVE-2024-5057WordPress Easy Digital Downloads plugin <= 3.2.12 - SQL Injection vulnerability9.3
  14. CVE-2024-6692Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text3.3
  15. CVE-2024-6691Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Currency Settings4.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store