Cross-Site Request Forgery Vulnerability in Easy Digital Downloads Plugin for WordPress
CVE-2026-7533

4.3MEDIUM

What is CVE-2026-7533?

The Easy Digital Downloads plugin for WordPress has a vulnerability due to missing nonce verification in its handling of OAuth redirects. This shortcoming permits unauthenticated attackers to exploit the handle_oauth_redirect() function, which is triggered on the admin_init hook. Through a maliciously crafted link, an attacker can deceive a logged-in administrator into executing unwanted actions that compromise the store's Square payment gateway credentials. Without adequate CSRF protection, this can lead to unauthorized access and potential hijacking of payment accounts, posing significant security risks for the affected WordPress sites.

Affected Version(s)

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy 0 <= 3.6.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

M Indra Purnama
.