CVE · Medium

CVE-2022-33900 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.1.4.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-33900 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.1.4.2 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Medium 4.1 < 3.1.1.4.2 3.1.1.4.2 2022-08-10

CVE-2022-33900

The Easy Digital Downloads plugin for WordPress contained a PHP object injection flaw in versions 3.0.1 and earlier that could be exploited by attackers. This vulnerability allows remote code execution or other malicious actions through unserialization of untrusted data. Users should upgrade to version 3.0.2 or later to patch this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.