CVE-2026-105194: Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Downloads Block
The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Easy Digital Downloadsto a version that resolves this vulnerability.Fixed in 3.7.1