Record summary

CVE-2023-23489 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 4, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Easy Digital Downloads WordPress Plugin

CVE List< 3.1.0.4affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL InjectionCVSS 9.8

WordPress Easy Digital Downloads plugin 3.1.0.2 and 3.1.0.3 contains a SQL injection vulnerability in the s parameter of its edd_download_search action. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.

Remediation

Update to the latest version of Easy Digital Downloads plugin (3.1.0.4 or higher) to mitigate the SQL Injection vulnerability.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2023easy-digital-downloadsunauthwpscanwordpresswpwp-pluginsqlitenablesandhillsdev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:sandhillsdev:easy_digital_downloads:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2