Cross-Site Scripting
14 records31.8%First: 2015. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 44 vulnerability records associated with Easy Digital Downloads – eCommerce Payments and Subscriptions made easy, published between 2015 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2015 | 2 | |
| 2016 | 1 | |
| 2019 | 1 | |
| 2020 | 1 | |
| 2021 | 5 | |
| 2022 | 5 | |
| 2023 | 6 | |
| 2024 | 12 | |
| 2025 | 6 | |
| 2026 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 6 | 13.6% |
| High | 5 | 11.4% |
| Medium | 31 | 70.5% |
| Low | 2 | 4.5% |
First: 2015. Latest: 2025.
First: 2021. Latest: 2026.
First: 2016. Latest: 2025.
First: 2023. Latest: 2026.
First: 2020. Latest: 2024.
First: 2024. Latest: 2025.
First: 2024. Latest: 2026.
First: 2023. Latest: 2023.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.6.9.13.6.83.6.63.6.33.5.33.5.13.3.93.3.73.3.53.3.43.3.33.3.13.2.123.2.103.2.73.2.63.2.03.1.23.1.1.4.23.1.0.53.1.0.43.03.1.0.23.0.22.11.62.11.2.12.10.42.10.32.3.32.9.162.5.82.3.72.2.92.1.112.0.51.9.101.8.7Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.6.9 | Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter | July 28, 2026 | 3.6.9.1 | High |
*-3.6.9 | Easy Digital Downloads <= 3.6.9 - Authenticated (Admin) Arbitrary File Deletion | July 27, 2026 | 3.6.9.1 | Medium |
*-3.6.7 | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.7 - Missing Authorization | July 22, 2026 | 3.6.8 | Medium |
*-3.6.7 | Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter | May 27, 2026 | 3.6.8 | Medium |
*-3.6.5 | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.5 - Missing Authorization | April 20, 2026 | 3.6.6 | Medium |
*-3.6.2 | Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect | December 30, 2025 | 3.6.3 | Medium |
*-3.5.2 | Easy Digital Download <= 3.5.2 - Insufficient Verification to Order Manipulation | November 5, 2025 | 3.5.3 | Medium |
*-3.5.0 | Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions | August 19, 2025 | 3.5.1 | Medium |
*-3.3.8.1 | Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode | May 28, 2025 | 3.3.9 | Medium |
*-3.3.6.1 | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure | March 24, 2025 | 3.3.7 | Medium |
*-3.3.2 | Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title | January 17, 2025 | 3.3.3 | Medium |
*-3.3.2 | Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Download | December 20, 2024 | 3.3.3 | Medium |
3.1-3.3.4 | Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass | December 16, 2024 | 3.3.5 | Low |
*-3.3.3 | Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR Deserialization | September 23, 2024 | 3.3.4 | High |
*-3.3.2 | Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text | August 9, 2024 | 3.3.3 | Low |
*-3.3.2 | Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Currency Settings | August 9, 2024 | 3.3.3 | Medium |
*-3.2.12 | Easy Digital Downloads <= 3.2.12 - Missing Authorization | August 7, 2024 | 3.3.1 | Medium |
*-3.2.12 | Easy Digital Downloads <= 3.2.12 - Unauthenticated SQL Injection | August 1, 2024 | 3.3.1 | Critical |
*-3.2.11 | Easy Digital Downloads <= 3.2.11 - Unauthenticated Sensitive Information Exposure | May 9, 2024 | 3.2.12 | Medium |
*-3.2.11 | Easy Digital Downloads <= 3.2.11 - Cross-Site Request Forgery | May 9, 2024 | 3.2.12 | Medium |
*-3.2.6 | Easy Digital Downloads <= 3.2.6 - Cross-Site Request Forgery | April 5, 2024 | 3.2.7 | Medium |
*-3.2.9 | Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information Exposure | April 3, 2024 | 3.2.10 | Medium |
*-3.2.6 | Easy Digital Downloads <= 3.2.6 - Authenticated(Shop Manager+) Stored Cross-Site Scripting via variable pricing options | February 2, 2024 | 3.2.7 | Medium |
*-3.2.5 | Easy Digital Downloads <= 3.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting | December 27, 2023 | 3.2.6 | Medium |
*-3.1.5 | Easy Digital Downloads <= 3.1.5 - Missing Authorization | December 26, 2023 | 3.2.0 | Medium |
Selected source records
Published: July 28, 2026
Published: July 27, 2026
Published: July 22, 2026
Published: May 27, 2026
Published: April 20, 2026
Published: December 30, 2025
Published: November 5, 2025
Published: August 19, 2025
Published: August 1, 2024
Published: January 12, 2023
Published: September 22, 2020
Published: May 2, 2023
Published: March 2, 2016
Published: August 10, 2022
Published: April 9, 2022
Published: September 28, 2022
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.