Executive brief
Easy Digital Downloads is a popular WordPress plugin used by businesses to sell digital products online. A security flaw in versions 3.6.5 and earlier allows unauthorized individuals to bypass access controls, potentially allowing them to perform administrative actions or modify store settings without a password. This could lead to unauthorized changes to product listings, pricing, or store configurations, impacting business operations and revenue.
Technical details
A broken access control vulnerability exists in the Easy Digital Downloads plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without user interaction. An attacker can leverage this to modify data or settings within the plugin's environment. The issue is addressed in version 3.6.6.
Affected products
- Easy Digital Downloads Easy Digital Downloads <= 3.6.5
Timeline
- 2026-02-12: other: Reported by Jakub Herman
- 2026-04-20: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date