PLUGIN SECURITY

Is Easy Digital Downloads safe?

The #1 eCommerce plugin to sell digital products & subscriptions. Accept payments with Stripe & PayPal. Sell ebooks, software & more.

What this plugin does

  • Slug: easy-digital-downloads
  • Author: Syed Balkhi
  • 40000+ active installs
  • 94/100 rating (590 reviews on wordpress.org)
  • 6081602 all-time downloads
  • On WordPress.org since 2012-04-10

digital storeecommercepaymentssell digital productsstripe

Maintenance status

  • Latest known version: 3.6.9.1
  • Last updated: 2026-08-14 4:55am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 8.0+

Known vulnerabilities

68 known CVEs on file for Easy Digital Downloads.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12476 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.9.1 Unrestricted Upload of File with Dangerous Type High 7.2 < 3.6.9.1 3.6.9.1 2026-07-28 ✓ fixed in latest
CVE-2026-7533 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.8 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.6.8 3.6.8 2026-05-27 ✓ fixed in latest
CVE-2026-39503 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.6 Missing Authorization High 7.5 < 3.6.6 3.6.6 2026-04-20 ✓ fixed in latest
CVE-2025-14783 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.3 Weak Password Recovery Mechanism for Forgotten Password Medium 4.3 < 3.6.3 3.6.3 2025-12-30 ✓ fixed in latest
CVE-2025-11271 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.5.3 Reliance on Untrusted Inputs in a Security Decision Medium 5.3 < 3.5.3 3.5.3 2025-11-05 ✓ fixed in latest
CVE-2024-13517 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.4 < 3.3.3 3.3.3 2025-01-17 ✓ fixed in latest
CVE-2024-12875 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 External Control of File Name or Path Medium 4.9 < 3.3.3 3.3.3 2024-12-20 ✓ fixed in latest
CVE-2022-2439 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.4 Deserialization of Untrusted Data High 7.2 < 3.3.4 3.3.4 2024-09-23 ✓ fixed in latest
+ 81 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6691 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.0 < 3.3.3 3.3.3 2024-08-09 ✓ fixed in latest
CVE-2024-6692 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Low 3.1 < 3.3.3 3.3.3 2024-08-09 ✓ fixed in latest
CVE-2024-43162 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.1 Missing Authorization High 8.8 < 3.3.1 3.3.1 2024-08-07 ✓ fixed in latest
CVE-2024-5057 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.3.1 3.3.1 2024-08-01 ✓ fixed in latest
CVE-2024-31113 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.12 Cross-Site Request Forgery (CSRF) High 8.8 < 3.2.12 3.2.12 2024-05-09 ✓ fixed in latest
CVE-2024-32100 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.12 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 3.2.12 3.2.12 2024-05-09 ✓ fixed in latest
CVE-2024-31293 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.7 Cross-Site Request Forgery (CSRF) High 8.8 < 3.2.7 3.2.7 2024-04-05 ✓ fixed in latest
CVE-2024-2302 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.10 Insertion of Sensitive Information into Log File Medium 5.3 < 3.2.10 3.2.10 2024-04-03 ✓ fixed in latest
CVE-2024-0659 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.2.7 3.2.7 2024-02-02 ✓ fixed in latest
CVE-2023-51684 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.2.6 3.2.6 2023-12-27 ✓ fixed in latest
CVE-2023-40005 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.2.0 Missing Authorization Medium 5.3 < 3.2.0 3.2.0 2023-12-26 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.2 Unknown < 3.1.2 3.1.2 2023-06-08 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.2 Unknown < 3.1.2 3.1.2 2023-06-07 ✓ fixed in latest
CVE-2023-30869 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] >= 3.1 - <= 3.1.1.4.1 Improper Authentication Critical 9.8 3.1–3.1.1.4.2 3.1.1.4.2 2023-05-01 ✓ fixed in latest
CVE-2023-0380 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.1.0.5 3.1.0.5 2023-01-30 ✓ fixed in latest
CVE-2023-23489 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.1.0.4 3.1.0.4 2023-01-12 ✓ fixed in latest
CVE-2022-2387 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.0 3.0 2022-10-17 ✓ fixed in latest
CVE-2022-3600 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.2 Improper Neutralization of Formula Elements in a CSV File Critical 9.8 < 3.1.0.2 3.1.0.2 2022-09-28 ✓ fixed in latest
CVE-2022-33900 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.1.4.2 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Medium 4.1 < 3.1.1.4.2 3.1.1.4.2 2022-08-10 ✓ fixed in latest
CVE-2022-0707 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.11.6 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.11.6 2.11.6 2022-03-28 ✓ fixed in latest
CVE-2022-0706 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.11.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.11.6 2.11.6 2022-03-28 ✓ fixed in latest
CVE-2021-39354 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.11.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.11.2.1 2.11.2.1 2021-10-21 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.11.2.1 Unknown < 2.11.2.1 2.11.2.1 2021-10-19 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.4 Unknown < 2.10.4 2.10.4 2021-05-04 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.3 Unknown < 2.10.3 2.10.3 2021-04-16 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.3 Unknown < 2.10.3 2.10.3 2021-04-16 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.3 Unknown < 2.10.3 2.10.3 2021-04-14 ✓ fixed in latest
CVE-2015-9517 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9518 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9510 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9526 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9528 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9530 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9531 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9516 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9535 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9521 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9534 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9525 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-23 ✓ fixed in latest
CVE-2015-9508 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2019-10-14 ✓ fixed in latest
CVE-2015-9324 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 2.3.3 2.3.3 2019-08-16 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.9.16 Unknown < 2.9.16 2.9.16 2019-06-16 ✓ fixed in latest
CVE-2019-15116 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.9.16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.9.16 2.9.16 2019-06-12 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.8 Unknown < 2.8 2.8 2017-03-31 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.5.8 Unknown < 2.5.8 2.5.8 2016-03-02 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.5.8 Unknown < 2.5.8 2.5.8 2016-03-02 ✓ fixed in latest
CVE-2015-9506 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9507 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9509 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9511 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9505, CVE-2015-9506, CVE-2015-9507, CVE-2015-9508, CVE-2015-9509, CVE-2015-9510, CVE-2015-9511, CVE-2015-9512, CVE-2015-9513, CVE-2015-9514, CVE-2015-9515, CVE-2015-9516, CVE-2015-9517, CVE-2015-9518, CVE-2015-9519, CVE-2015-9520, CVE-2015-9521, CVE-2015-9522, CVE-2015-9523, CVE-2015-9524, CVE-2015-9525, CVE-2015-9526, CVE-2015-9527, CVE-2015-9528, CVE-2015-9529, CVE-2015-9530, CVE-2015-9531 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9512 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9513 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9515 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9533 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9519 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9520 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9514 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9522 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9524 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9523 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9527 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9529 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9532 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
CVE-2015-9536 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-20 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] >= 3.1 - < 3.3.5 Incorrect Authorization Low 3.7 3.1–3.3.5 3.3.5 0000-00-00 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 3.3.7 3.3.7 0000-00-00 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.3.9 3.3.9 0000-00-00 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.5.1 Cross-Site Request Forgery (CSRF) Medium 5.4 < 3.5.1 3.5.1 0000-00-00 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.8 Unknown < 3.6.8 3.6.8 0000-00-00 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.9.1 Unknown < 3.6.9.1 3.6.9.1 0000-00-00 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.10.3 Unknown < 2.10.3 2.10.3 ✓ fixed in latest
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 2.5.8 Unknown < 2.5.8 2.5.8 ✓ fixed in latest
Easy Digital Downloads < 2.5.8 - PHP Object Injection Unknown < 2.5.8 2.5.8 ✓ fixed in latest
Easy Digital Downloads < 2.10.3 - Unauthorised Stripe Disconnect via CSRF Unknown < 2.10.3 2.10.3 ✓ fixed in latest
CVE-2024-9654 Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass Unknown < 3.3.5 3.3.5 ✓ fixed in latest
CVE-2025-2252 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy < 3.3.7 - Unauthenticated Private Post Title Disclosure Unknown < 3.3.7 3.3.7 ✓ fixed in latest
CVE-2025-4670 Easy Digital Downloads < 3.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcode Unknown < 3.3.9 3.3.9 ✓ fixed in latest
CVE-2025-8102 Easy Digital Downloads < 3.5.1 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions Unknown < 3.5.1 3.5.1 ✓ fixed in latest
CVE-2026-59524 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy < 3.6.8 - Missing Authorization Unknown < 3.6.8 3.6.8 ✓ fixed in latest
CVE-2026-66476 Easy Digital Downloads < 3.6.9.1 - Authenticated (Admin) Arbitrary File Deletion Unknown < 3.6.9.1 3.6.9.1 ✓ fixed in latest

How to fix it

Keep Easy Digital Downloads updated — 3.6.9.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.