CVE-2024-2302

MEDIUM

Awesomemotive Easy Digital Downloads - Log Information Exposure

Title source: rule
STIX 2.1

Description

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing. This file may include PII.

Scores

CVSS v3 5.3
EPSS 0.0098
EPSS Percentile 76.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (2)
awesomemotive/easy_digital_downloads < 3.2.10
smub/Easy Digital Downloads – eCommerce Payments and Subscriptions made easy < 3.2.9
Published Apr 09, 2024
Tracked Since Feb 18, 2026