Unauthorized Information Exposure in Easy Digital Downloads Plugin for WordPress
CVE-2024-9654

3.7LOW

Key Information:

Summary

CVE-2024-9654 is a critical vulnerability in the Easy Digital Downloads plugin for WordPress, affecting versions 3.1 to 3.3.4. This issue stems from improper authorization checks in the 'verify_guest_email' function, which fails to ensure that a requesting user is the rightful recipient of a purchase receipt. Consequently, this flaw allows unauthenticated attackers to bypass security protocols and gain access to the purchase receipts of other users. These receipts can potentially expose download links for paid content, requiring only the attacker's knowledge of another user's email address and the specific file ID. Website owners using this plugin should prioritize applying security updates to mitigate this risk.

Affected Version(s)

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy 3.1 <= 3.3.4

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arkadiusz Hydzik
.