SecAlerts
awesomemotive logo

awesomemotive

Security Risk Profile

38
/100
low

Security Risk Score

Comprehensive risk assessment based on 64 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 26, 2018 to present

64
Total CVEs
15
Critical+High
1
Exploited
9
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
9
Critical/High
Risk Level
38/100
low
⚠️ 1 Active Exploits

Severity Distribution

Critical
7
High
8
Medium
47
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
44
2
Infoleak
2
3
Path Traversal
2
4
SQL Injection
2
5
Code Injection
2

Most Affected Products

1. Awesomemotive Easy Digital Downloads Wordpress215
2. Sandhillsdev Easy Digital Downloads Wordpress201
3. Awesomemotive Duplicator Wordpress10
4. Easy Digital Downloads Easy Digital Downloads8
5. SnapCreek Duplicator Wordpress6

Recent Vulnerabilities

See more →
CVE-2025-4670
CVSS 6.4EPSS 0%medium

Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode

5/29/2025🔧 No Patch
CVE-2025-2252
CVSS 5.3medium

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure

3/25/2025🔧 No Patch
CVE-2024-13517
CVSS 4.4medium

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title

1/18/2025
CVE-2024-12875
CVSS 4.9medium

Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Download

12/21/2024
CVE-2024-9654
CVSS 3.7EPSS 0%low

Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass

12/17/2024
CVE-2023-40005
CVSS 9.8critical

WordPress Easy Digital Downloads plugin <= 3.1.5 - Broken Access Control

12/13/2024
CVE-2024-43162
CVSS 8.8high

WordPress Easy Digital Downloads plugin <= 3.2.12 - Broken Access Control vulnerability

11/1/2024
CVE-2022-2439
CVSS 7.2high

Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR Deserialization

9/24/2024
CVE-2024-5057
CVSS 9.8critical

WordPress Easy Digital Downloads plugin <= 3.2.12 - SQL Injection vulnerability

8/29/2024
CVE-2024-6692
CVSS 3.3EPSS 0%low

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text

8/10/2024

Monitor awesomemotive in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.