First published: Fri Dec 13 2024(Updated: )
Missing Authorization vulnerability in Easy Digital Downloads Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.1.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Digital Downloads | <3.2.0 | |
Easy Digital Downloads | <=3.1.5 | |
Easy Digital Downloads | <=3.1.5 |
Update the WordPress Easy Digital Downloads plugin to the latest available version (at least 3.2.0).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40005 is considered a medium severity vulnerability due to its impact on access control.
To fix CVE-2023-40005, upgrade Easy Digital Downloads to version 3.2.0 or later.
CVE-2023-40005 affects Easy Digital Downloads versions up to 3.1.5.
CVE-2023-40005 is a missing authorization vulnerability leading to incorrect access control.
As of now, there are no known public exploits for CVE-2023-40005, but it is advisable to apply the patch.