CVE · Medium

CVE-2024-6691 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6691 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.0 < 3.3.3 3.3.3 2024-08-09

CVE-2024-6691

The Easy Digital Downloads plugin for WordPress contains a security flaw in versions up to 3.3.2, which allows attackers with administrator-level access to inject malicious scripts into certain pages through the currency value input field. This vulnerability is specific to multi-site setups and installations where unfiltered HTML has been restricted, enabling authenticated attackers to execute arbitrary web code when users visit affected pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.