CVE-2023-30869
WordPress Easy Digital Downloads Plugin 3.1-3.1.1.4.1 is vulnerable to Privilege Escalation
Record summary
CVE-2023-30869 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 2, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 8, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Easy Digital DownloadsBrowse Easy Digital Downloads / Easy Digital DownloadsDefault status: unaffected | CVE List | 3.1 to ≤ 3.1.1.4.1 | affected |
easy_digital_downloadsBrowse awesomemotive / easy_digital_downloads | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALEasy Digital Downloads - Privilege EscalationCVSS 9.8
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.
Impact
Unauthenticated attackers can exploit improper authentication in the password reset functionality to reset any user's password and gain administrative access to WordPress sites using Easy Digital Downloads.
Remediation
Update Easy Digital Downloads plugin to a version newer than 3.1.1.4.1 that properly authenticates password reset requests and prevents unauthorized privilege escalation.
Source: ProjectDiscovery