PT-2025-34039 · WordPress · Sendwp+1
Wesley
·
Published
2025-08-20
·
Updated
2025-08-20
·
CVE-2025-8102
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Easy Digital Downloads versions prior to 3.5.1
Description:
The Easy Digital Downloads plugin for WordPress is susceptible to Cross-Site Request Forgery due to missing nonce validations in the
edd sendwp disconnect() and edd sendwp remote install() functions. This allows unauthenticated attackers to deactivate or download and activate the SendWP plugin through a forged request by tricking a site administrator into performing an action, such as clicking a link.Recommendations:
Update Easy Digital Downloads to version 3.5.1 or later.
As a temporary workaround, consider disabling the SendWP plugin until a patch is available.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Digital Downloads
Sendwp