CVE · Critical

CVE-2022-3600 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3600 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.2 Improper Neutralization of Formula Elements in a CSV File Critical 9.8 < 3.1.0.2 3.1.0.2 2022-09-28

CVE-2022-3600

The Easy Digital Downloads plugin for WordPress before version 3.1.0.2 contains a CSV injection vulnerability that allows unauthenticated attackers to insert malicious content into exported CSV files. When a user downloads and opens these compromised files in a spreadsheet application with vulnerable settings, the embedded code can execute on their local system, potentially compromising their security.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.