CVE-2026-59524: WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vulnerability
Published Jul 23, 2026
·Updated
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
Affected Software
1 affected component
WordPress Easy Digital Downloads<=3.6.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Easy Digital Downloads pluginto a version that resolves this vulnerability.Fixed in 3.6.8
Event History
Jul 23, 2026
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-59524?
The severity of CVE-2026-59524 is medium with a score of 6.5.
2
How do I fix CVE-2026-59524?
To fix CVE-2026-59524, update the Easy Digital Downloads plugin to version 3.6.8 or later.
3
What type of vulnerability is CVE-2026-59524?
CVE-2026-59524 is identified as an Unauthenticated Broken Authentication vulnerability.
4
What versions of Easy Digital Downloads are affected by CVE-2026-59524?
Easy Digital Downloads versions 3.6.7 and earlier are affected by CVE-2026-59524.
5
What impact does CVE-2026-59524 have on my website?
CVE-2026-59524 could allow attackers to exploit authentication mechanisms and gain unauthorized access to features.