Access Control Issues in Easy Digital Downloads Plugin for WordPress
CVE-2026-105194
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 8 October 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-105194?
The Easy Digital Downloads plugin for WordPress prior to version 3.7.1 is vulnerable due to inadequate restrictions on order data visibility. This flaw allows users with only subscriber-level access to view details of other customers' recent orders, including signed download links that provide unauthorized access to paid digital files. As a result, this vulnerability poses a significant risk, enabling potential data breaches and unauthorized content access without proper purchase.
Affected Version(s)
Easy Digital Downloads 0 < 3.7.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.