CVE-2026-105194
Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Downloads Block
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase.
| Vendor | unknown |
| Product | easy digital downloads |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown easy digital downloads
Be the first to know when new unknown vulnerabilities affecting unknown easy digital downloads are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Easy Digital Downloads
0 < 3.7.1
References
Credits
Muni Nitish Kumar Yaddala WPScan