CVE-2021-39354: Easy Digital Downloads <= 2.11.2 Authenticated Reflected Cross-Site Scripting
The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $startdate and $enddate parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39354?
CVE-2021-39354 is rated as a high severity vulnerability due to its potential for exploit through reflected cross-site scripting.
How do I fix CVE-2021-39354?
To fix CVE-2021-39354, update the Easy Digital Downloads plugin to version 2.11.3 or later.
What type of vulnerability is CVE-2021-39354?
CVE-2021-39354 is a reflected cross-site scripting vulnerability affecting the Easy Digital Downloads WordPress plugin.
Which versions of Easy Digital Downloads are affected by CVE-2021-39354?
CVE-2021-39354 affects all versions of Easy Digital Downloads up to and including 2.11.2.
What parameters are exploited in CVE-2021-39354?
CVE-2021-39354 exploits the $start_date and $end_date parameters in the class-payments-table.php file.