Impact
This vulnerability allows an unauthenticated attacker to inject arbitrary JavaScript into pages rendered by the Easy Digital Downloads plugin. The injected payload is stored via PayPal IPN parameters and subsequently rendered in the plugin’s reporting interface. Any user who views the affected page will execute the attacker’s script, leading to theft of browser cookies, session hijacking, or the execution of further malicious actions on behalf of that user. The weakness is a classic example of insufficient input sanitization and output escaping, labeled CWE-79.
Affected Systems
All installations of the Easy Digital Downloads WordPress plugin up to and including version 3.6.9 are affected. The issue resides in the PayPal IPN handling code used by the plugin.
Risk and Exploitability
The CVSS score of 7.2 classifies the flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the nature of the flaw enables attackers to execute arbitrary scripts in users’ browsers without authentication. If the attacker can reach the PayPal IPN endpoint, the stored payload will persist in the database and be delivered to any user who accesses the reporting page. This makes exploitation relatively straightforward in poorly secured or exposed installations and poses significant confidentiality, integrity, and availability risks to site visitors.
OpenCVE Enrichment