๐Ÿ” CVE Alert

CVE-2026-105194

UNKNOWN 0.0

Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Downloads Block

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase.

Vendor unknown
Product easy digital downloads
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown easy digital downloads

Be the first to know when new unknown vulnerabilities affecting unknown easy digital downloads are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Easy Digital Downloads
0 < 3.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/aa49b193-8409-436f-a034-70b166afc483/

Credits

Muni Nitish Kumar Yaddala WPScan