PT-2025-12768 · WordPress · Easy Digital Downloads
Françoa Taffarel
·
Published
2025-03-25
·
Updated
2025-08-08
·
CVE-2025-2252
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Easy Digital Downloads – eCommerce Payments and Subscriptions plugin for WordPress versions up to, and including, 3.3.6.1
Description
The issue allows unauthenticated attackers to extract private post titles of downloads via the
edd ajax get download title() function. The impact of this issue is minimal.Recommendations
For versions up to, and including, 3.3.6.1, consider updating to a version that contains a fix for this issue, as no specific mitigation measures are provided for these versions.
As a temporary workaround, consider disabling the
edd ajax get download title() function until a patch is available.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Digital Downloads