SecAlerts
easy digital downloads logo

easy digital downloads

Security Risk Profile

25
/100
low

Security Risk Score

Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 9, 2024 to present

18
Total CVEs
6
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
25/100
low

Severity Distribution

Critical
1
High
5
Medium
10
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
CSRF
5
2
XSS
5
3
Infoleak
2
4
Path Traversal
1

Most Affected Products

1. Easy Digital Downloads Easy Digital Downloads14
2. Awesomemotive Easy Digital Downloads Wordpress11
3. WordPress Easy Digital Downloads4
4. Sandhillsdev Easy Digital Downloads Wordpress3
5. Easy Digital Downloads eCommerce Payments and Subscriptions2

Recent Vulnerabilities

See more →
CVE-2026-7533
CVSS 4.3medium

Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter

5/28/2026🔧 No Patch
CVE-2025-11271
CVSS 5.3medium

Easy Digital Download <= 3.5.2 - Insufficient Verification to Order Manipulation

11/6/2025🔧 No Patch
CVE-2025-8102
CVSS 5.4EPSS 0%medium

Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions

8/20/2025🔧 No Patch
CVE-2025-4670
CVSS 6.4EPSS 0%medium

Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode

5/29/2025🔧 No Patch
CVE-2023-2334
CVSS 5.4medium

Easy Digital Downloads Google Sheet Connector < 1.6.6 - Access Code Update via CSRF

5/15/2025🔧 No Patch
CVE-2025-2252
CVSS 5.3medium

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure

3/25/2025🔧 No Patch
CVE-2024-13517
CVSS 4.4medium

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title

1/18/2025
CVE-2024-12875
CVSS 4.9medium

Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Download

12/21/2024
CVE-2024-9654
CVSS 3.7EPSS 0%low

Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass

12/17/2024
CVE-2023-40005
CVSS 9.8critical

WordPress Easy Digital Downloads plugin <= 3.1.5 - Broken Access Control

12/13/2024

Monitor easy digital downloads in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.