Executive brief
Easy Digital Downloads, a popular WordPress plugin for managing digital sales, contains a security flaw that could allow unauthorized individuals to bypass authentication. This vulnerability could potentially allow an attacker to perform actions usually reserved for high-privileged users, which may lead to unauthorized access to the website's administrative functions. Business operations could be impacted by unauthorized changes to the store or potential data exposure.
Technical details
Easy Digital Downloads (<= 3.6.7) is vulnerable to an authentication bypass using an alternate path or channel (CWE-288). The vulnerability allows an unauthenticated remote attacker to bypass security checks and perform actions that should be restricted to higher-privileged users. According to the advisory, this could lead to gaining administrative access to the WordPress site. The issue is resolved in version 3.6.8. The CVSS vector indicates a network-based attack with low complexity and no user interaction required, though the impact is primarily on integrity and availability.
Affected products
- Sandhills Development, LLC Easy Digital Downloads <= 3.6.7
Timeline
- 2026-04-30: other: Reported by James Paremain
- 2026-07-22: patched: Version 3.6.8 released
- 2026-07-23: disclosed: NVD publication date