Description
The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized access to paid digital content
Action: Immediate Patch
AI Analysis

Impact

Easy Digital Downloads, a popular WordPress plugin, contains a flaw in versions prior to 3.7.1 that fails to enforce user restrictions on the order data displayed in the Downloads block. As a result, a subscriber‑level user can view recent order information belonging to other customers and capture signed download links that grant unauthorized access to paid digital files. The flaw enables violation of confidentiality and may lead to revenue loss and privacy exposure, reflecting an information disclosure and improper access control weakness.

Affected Systems

Affected systems include the Easy Digital Downloads WordPress plugin for any installation using a version earlier than 3.7.1. No other product versions or vendors are listed in the CNA source, but any site running the vulnerable plugin is at risk.

Risk and Exploitability

While an explicit CVSS score is not provided and the EPSS score is unavailable, the vulnerability can be exploited by authenticated subscriber users who already have login access. The attacker needs only the ability to load the Downloads block, making the attack relatively simple once authenticated. Because the vulnerability relies on existing user roles rather than a public remote exploitation vector, the risk is moderate to high for sites with many subscriber accounts, yet no publicly disclosed exploits are known.

Generated by OpenCVE AI on October 8, 2026 at 07:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Easy Digital Downloads to version 3.7.1 or newer.
  • Ensure that the Downloads block is configured to show order data only for the current user, and that role permissions enforce this restriction.
  • If upgrading immediately is not possible, limit subscriber‑level access to the Orders/Downloads section by adjusting capability settings or using a role‑based plugin to prevent cross‑user visibility.

Generated by OpenCVE AI on October 8, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase.
Title Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Downloads Block
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:06.727Z

Reserved: 2026-10-04T11:56:00.085Z

Link: CVE-2026-105194

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:39.763

Modified: 2026-10-08T06:16:39.763

Link: CVE-2026-105194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:30:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control