CVE-2025-2252: Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the eddajaxgetdownloadtitle() function. This makes it possible for unauthenticated attackers to extract private post titles of downloads. The impact here is minimal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2252?
CVE-2025-2252 is rated as a high-severity vulnerability due to its potential for exposing sensitive information.
How do I fix CVE-2025-2252?
To fix CVE-2025-2252, update the Easy Digital Downloads eCommerce Payments and Subscriptions plugin to version 3.3.6.2 or later.
Who is affected by CVE-2025-2252?
All versions of the Easy Digital Downloads eCommerce Payments and Subscriptions plugin up to and including 3.3.6.1 are vulnerable to CVE-2025-2252.
What is the main issue of CVE-2025-2252?
The main issue of CVE-2025-2252 is sensitive information exposure through the edd_ajax_get_download_title() function.
Can unauthenticated users exploit CVE-2025-2252?
Yes, unauthenticated users can exploit CVE-2025-2252 to access sensitive information.