Arbitrary File Deletion in Easy Digital Downloads by Pippins Plugins
CVE-2026-66476
4.9MEDIUM
What is CVE-2026-66476?
The Easy Digital Downloads plugin for WordPress, specifically versions up to and including 3.6.9, contains a vulnerability that allows administrators to arbitrarily delete files from the server. This issue arises from the way the plugin handles file deletion requests, potentially leading to unauthorized removal of critical files. Website owners utilizing this plugin should take immediate steps to secure their installations and consider upgrading to a patched version.
Affected Version(s)
Easy Digital Downloads <= 3.6.9
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program