PT-2024-17771 · WordPress · Easy Digital Downloads

Jack_Sparrow

+1

·

Published

2024-12-21

·

Updated

2024-12-21

·

CVE-2024-12875

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress versions up to 3.3.2
Description The issue allows authenticated attackers with Administrator-level access and above to read the contents of arbitrary files on the server via the file download functionality. This can potentially expose sensitive information.
Recommendations For versions up to 3.3.2, update to a version higher than 3.3.2 to resolve the issue. As a temporary workaround, consider restricting access to the file download functionality until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-12875

Affected Products

Easy Digital Downloads