PT-2025-12768 · WordPress · Easy Digital Downloads

Françoa Taffarel

·

Published

2025-03-25

·

Updated

2025-08-08

·

CVE-2025-2252

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easy Digital Downloads – eCommerce Payments and Subscriptions plugin for WordPress versions up to, and including, 3.3.6.1
Description The issue allows unauthenticated attackers to extract private post titles of downloads via the edd ajax get download title() function. The impact of this issue is minimal.
Recommendations For versions up to, and including, 3.3.6.1, consider updating to a version that contains a fix for this issue, as no specific mitigation measures are provided for these versions. As a temporary workaround, consider disabling the edd ajax get download title() function until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-2252

Affected Products

Easy Digital Downloads