CVE Database /
CVE-2024-6691
CVE · Medium
CVE-2024-6691 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-6691
|
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.0
|
< 3.3.3
|
3.3.3 |
2024-08-09 |
—
|
CVE-2024-6691
The Easy Digital Downloads plugin for WordPress contains a security flaw in versions up to 3.3.2, which allows attackers with administrator-level access to inject malicious scripts into certain pages through the currency value input field. This vulnerability is specific to multi-site setups and installations where unfiltered HTML has been restricted, enabling authenticated attackers to execute arbitrary web code when users visit affected pages.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings