Impact
Easy Digital Downloads, a popular WordPress plugin, contains a flaw in versions prior to 3.7.1 that fails to enforce user restrictions on the order data displayed in the Downloads block. As a result, a subscriber‑level user can view recent order information belonging to other customers and capture signed download links that grant unauthorized access to paid digital files. The flaw enables violation of confidentiality and may lead to revenue loss and privacy exposure, reflecting an information disclosure and improper access control weakness.
Affected Systems
Affected systems include the Easy Digital Downloads WordPress plugin for any installation using a version earlier than 3.7.1. No other product versions or vendors are listed in the CNA source, but any site running the vulnerable plugin is at risk.
Risk and Exploitability
While an explicit CVSS score is not provided and the EPSS score is unavailable, the vulnerability can be exploited by authenticated subscriber users who already have login access. The attacker needs only the ability to load the Downloads block, making the attack relatively simple once authenticated. Because the vulnerability relies on existing user roles rather than a public remote exploitation vector, the risk is moderate to high for sites with many subscriber accounts, yet no publicly disclosed exploits are known.
OpenCVE Enrichment