CVE-2024-2302: Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information Exposure
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing. This file may include PII.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2302?
CVE-2024-2302 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2024-2302?
To mitigate CVE-2024-2302, update the Easy Digital Downloads plugin to version 3.3.0 or higher.
What versions are affected by CVE-2024-2302?
CVE-2024-2302 affects all versions of Easy Digital Downloads up to and including 3.2.9.
Who can exploit CVE-2024-2302?
CVE-2024-2302 can be exploited by unauthenticated attackers to access the debug log.
What type of vulnerability is CVE-2024-2302?
CVE-2024-2302 is a Sensitive Information Exposure vulnerability.