Showing 2 vulnerabilities on this page for easy_digital_downloads

Signals CISA KEV Ransomware Nuclei
awesomemotive vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Easy Digital Downloads plugin <= 3.2.12 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.

CWE-89Aug 29, 20241 related artifact
CVSS9.3v3.1EPSS2.59%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress Easy Digital Downloads Plugin 3.1-3.1.1.4.1 is vulnerable to Privilege Escalation

Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.

CWE-287May 2, 20231 related artifact
CVSS9.8v3.1EPSS3.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX