PT-2024-12834 · Unknown · Easy Digital Downloads

Nguyen Anh Tien

·

Published

2024-12-13

·

Updated

2024-12-17

·

CVE-2023-40005

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easy Digital Downloads versions 3.1.5 and earlier
Description The issue affects Easy Digital Downloads, allowing exploitation of incorrectly configured access control security levels due to a missing authorization vulnerability. This involves broken access control, which can be exploited.
Recommendations For versions 3.1.5 and earlier, update to the latest version to remediate the issue and mitigate risks. As a temporary workaround, consider restricting access to sensitive areas of the plugin until a patch is applied.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-40005

Affected Products

Easy Digital Downloads