First published: Tue Apr 09 2024(Updated: )
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing. This file may include PII.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Digital Downloads | <=3.2.9 | |
Easy Digital Downloads | <3.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2302 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To mitigate CVE-2024-2302, update the Easy Digital Downloads plugin to version 3.3.0 or higher.
CVE-2024-2302 affects all versions of Easy Digital Downloads up to and including 3.2.9.
CVE-2024-2302 can be exploited by unauthenticated attackers to access the debug log.
CVE-2024-2302 is a Sensitive Information Exposure vulnerability.