PT-2024-17771 · WordPress · Easy Digital Downloads
Jack_Sparrow
+1
·
Published
2024-12-21
·
Updated
2024-12-21
·
CVE-2024-12875
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress versions up to 3.3.2
Description
The issue allows authenticated attackers with Administrator-level access and above to read the contents of arbitrary files on the server via the file download functionality. This can potentially expose sensitive information.
Recommendations
For versions up to 3.3.2, update to a version higher than 3.3.2 to resolve the issue. As a temporary workaround, consider restricting access to the file download functionality until a patch is available.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easy Digital Downloads