CVE-2026-7533: Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the handleoauthredirect() function, which is registered on the admininit hook and processes Square OAuth tokens from a user-supplied GET parameter without any CSRF token validation. This makes it possible for unauthenticated attackers to overwrite the store's Square payment gateway credentials by tricking a logged-in administrator into clicking a crafted link, potentially resulting in payment account hijacking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7533?
The severity of CVE-2026-7533 is classified as medium with a score of 4.3.
How do I fix CVE-2026-7533?
To fix CVE-2026-7533, update the Easy Digital Downloads plugin to version 3.6.8 or later, where the nonce verification has been implemented.
What type of vulnerability is CVE-2026-7533?
CVE-2026-7533 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability.
What can attackers do with CVE-2026-7533?
With CVE-2026-7533, attackers can potentially hijack payment accounts through the 'square_tokens' parameter due to the lack of nonce verification.
Which versions of Easy Digital Downloads are affected by CVE-2026-7533?
CVE-2026-7533 affects all versions of Easy Digital Downloads up to and including 3.6.7.