CVE · High

CVE-2022-2439 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2439 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.4 Deserialization of Untrusted Data High 7.2 < 3.3.4 3.3.4 2024-09-23

CVE-2022-2439

The Easy Digital Downloads plugin before version 3.3.4 contains a deserialization vulnerability in the 'upload[file]' parameter that allows authenticated administrators to exploit PHP object injection through PHAR wrapper functionality. An attacker with admin privileges could leverage this flaw to execute arbitrary code if a suitable property-oriented programming chain exists within the application or its dependencies. The vulnerability affects versions up to and including 3.3.3 and was patched in 3.3.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.