Vulnerabilities (CVE)

Filtered by vendor Awesomemotive Subscribe
Filtered by product Easy Digital Downloads
Total 53 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-51684 1 Awesomemotive 1 Easy Digital Downloads 2025-02-07 N/A 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Digital Downloads Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) allows Stored XSS.This issue affects Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): from n/a through 3.2.5.
CVE-2015-9534 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Quota 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Quota theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9519 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Pdf Stamper 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9520 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Per Product Emails 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Per Product Emails extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9531 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Wish Lists 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2022-2387 1 Awesomemotive 1 Easy Digital Downloads 2025-02-07 N/A 4.3 MEDIUM
The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack
CVE-2015-9521 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Pushover Notifications 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2023-30869 1 Awesomemotive 1 Easy Digital Downloads 2025-02-07 N/A 9.8 CRITICAL
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.
CVE-2019-15116 1 Awesomemotive 1 Easy Digital Downloads 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
CVE-2015-9527 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Simple Shipping 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9513 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Favorites 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9526 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Reviews 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9535 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Shoppette 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9518 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Pdf Invoices 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) PDF Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9510 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Cross-sell And Upsell 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Cross-sell Upsell extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9511 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Conditional Success Redirects 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Conditional Success Redirects extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9528 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Software Licensing 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2024-5057 1 Awesomemotive 1 Easy Digital Downloads 2025-02-07 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.
CVE-2015-9524 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Recount Earnings 2025-02-07 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2021-39354 1 Awesomemotive 1 Easy Digital Downloads 2025-02-07 3.5 LOW 4.8 MEDIUM
The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.