Record summary

CVE-2023-30869 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 2, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 8, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List3.1 to ≤ 3.1.1.4.1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALEasy Digital Downloads - Privilege EscalationCVSS 9.8

Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.

Impact

Unauthenticated attackers can exploit improper authentication in the password reset functionality to reset any user's password and gain administrative access to WordPress sites using Easy Digital Downloads.

Remediation

Update Easy Digital Downloads plugin to a version newer than 3.1.1.4.1 that properly authenticates password reset requests and prevents unauthorized privilege escalation.

WeaknessesCWE-287
Authorsdaffainfo
Template tagscvecve2023wordpresswpwp-pluginawesomemotiveeasy_digital_downloadsauth-bypassintrusivevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3