SecAlerts
e

easy digital downloads

Security Risk Profile

25
/100
low

Security Risk Score

Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 9, 2024 to present

18
Total CVEs
6
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
25/100
low

Severity Distribution

Critical
1
High
5
Medium
10
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
CSRF
5
2
XSS
5
3
Infoleak
2
4
Path Traversal
1

Most Affected Products

1. Easy Digital Downloads Easy Digital Downloads14
2. Awesomemotive Easy Digital Downloads Wordpress11
3. WordPress Easy Digital Downloads4
4. Sandhillsdev Easy Digital Downloads Wordpress3
5. Easy Digital Downloads eCommerce Payments and Subscriptions2

Recent Vulnerabilities

See more →
CVE-2026-7533
CVSS 4.3medium

Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter

May 28, 2026🔧 No Patch
CVE-2025-11271
CVSS 5.3medium

Easy Digital Download <= 3.5.2 - Insufficient Verification to Order Manipulation

Nov 6, 2025🔧 No Patch
CVE-2025-8102
CVSS 5.4EPSS 0%medium

Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions

Aug 20, 2025🔧 No Patch
CVE-2025-4670
CVSS 6.4EPSS 0%medium

Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode

May 29, 2025🔧 No Patch
CVE-2023-2334
CVSS 5.4medium

Easy Digital Downloads Google Sheet Connector < 1.6.6 - Access Code Update via CSRF

May 15, 2025🔧 No Patch
CVE-2025-2252
CVSS 5.3medium

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure

Mar 25, 2025🔧 No Patch
CVE-2024-13517
CVSS 4.4medium

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title

Jan 18, 2025
CVE-2024-12875
CVSS 4.9medium

Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Download

Dec 21, 2024
CVE-2024-9654
CVSS 3.7EPSS 0%low

Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass

Dec 17, 2024
CVE-2023-40005
CVSS 9.8critical

WordPress Easy Digital Downloads plugin <= 3.1.5 - Broken Access Control

Dec 13, 2024

Monitor easy digital downloads in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

easy digital downloads Security Vulnerabilities & Risk Score | 18 CVEs | SecAlerts - SecAlerts