QID 730695

Date Published: 2023-01-17

QID 730695: WordPress Plugin Easy Digital Downloads SQL Injection Vulnerability

Easy Digital Downloads is a complete eCommerce solution for selling digital products on WordPress.

CVE-2023-23489: Parameter used in the 'edd_download_search' AJAX action in wordpress plugin easy digital downloads is vulnerable to SQL Injection.

Affected Versions:
Easy Digital Downloads versions 3.1.0.2 and 3.1.0.3

QID Detection Logic(Unauthenticated): This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Easy Digital Downloads plugin.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are requested to update to Easy Digital Downloads Plugin 3.1.0.4 or later to mitigate this vulnerability.

    Vendor References

    CVEs related to QID 730695

    Software Advisories
    Advisory ID Software Component Link
    Easy Digital Downloads Release Notes URL Logo wordpress.org/plugins/easy-digital-downloads/#developers