CVE Tools

Easy Digital Downloads – Ecommerce Payments and Subscriptions Made Easy

15 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Easy Digital Downloads – Ecommerce Payments and Subscriptions Made Easy, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Easy Digital Downloads – Ecommerce Payments and Subscriptions Made Easy CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Easy Digital Downloads – Ecommerce Payments and Subscriptions Made Easy CVEs per month
MonthCVEs
2024-100
2024-110
2024-122
2025-011
2025-020
2025-031
2025-040
2025-051
2025-060
2025-070
2025-081
2025-090
2025-100
2025-111
2025-121
2026-010
2026-020
2026-030
2026-040
2026-051
2026-060
2026-071
2026-080
2026-090

Severity

How the 15 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High213%
  • Medium1173%
  • Low213%

Latest CVEs

The 15 most recently published vulnerabilities affecting Easy Digital Downloads – Ecommerce Payments and Subscriptions Made Easy.

  1. CVE-2026-12476Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter7.2
  2. CVE-2026-7533Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter4.3
  3. CVE-2025-14783Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect4.3
  4. CVE-2025-11271Easy Digital Download <= 3.5.2 - Insufficient Verification to Order Manipulation5.3
  5. CVE-2025-8102Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions5.4
  6. CVE-2025-4670Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode6.4
  7. CVE-2025-2252Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure5.3
  8. CVE-2024-13517Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title4.4
  9. CVE-2024-12875Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Download4.9
  10. CVE-2024-9654Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass3.7
  11. CVE-2022-2439Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR Deserialization7.2
  12. CVE-2024-6692Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text3.3
  13. CVE-2024-6691Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Currency Settings4.4
  14. CVE-2024-2302Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information Exposure5.3
  15. CVE-2024-0659Easy Digital Downloads <= 3.2.6 - Authenticated(Shop Manager+) Stored Cross-Site Scripting via variable pricing options5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store