First published: Tue May 02 2023(Updated: )
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sandhillsdev Easy Digital Downloads | >=3.1<3.1.1.4.2 |
Update to 3.1.1.4.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-30869 is critical with a score of 9.8.
Easy Digital Downloads plugin versions 3.1 through 3.1.1.4.1 are affected by CVE-2023-30869.
CVE-2023-30869 is an Improper Authentication vulnerability in the Easy Digital Downloads plugin which allows unauthorized privilege escalation.
To fix CVE-2023-30869, update Easy Digital Downloads plugin to version 3.1.1.4.2 or higher.
You can find more information about CVE-2023-30869 at the following references: [1](https://patchstack.com/articles/critical-easy-digital-downloads-vulnerability?_s_id=cve) and [2](https://patchstack.com/database/vulnerability/easy-digital-downloads/wordpress-easy-digital-downloads-plugin-3-1-1-4-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve).