Impact
The vulnerability is an unauthenticated broken access control flaw that allows an attacker to bypass authorization checks and gain unauthorized access to privileged functions within the Easy Digital Downloads WordPress plugin. This flaw can enable an attacker to view, modify, or delete sensitive content, such as downloads, orders authenticating. The weakness is classified as CWE-862.
Affected Systems
The issue affects the Awesomemotive Easy Digital Downloads plugin for WordPress up to and including version 3.6.5. Any website that has not upgraded from these versions is vulnerable. Version 3.6.6 and later contain the necessary fix.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is reported as less than 1%, suggesting a very low probability of exploitation in the wild at the time of analysis, and it is not listed in the CISA KEV catalog. The attack path is straightforward: an unauthenticated user can target privileged endpoints exposed by the plugin, since the access control checks are missing. Because no credentials are required, any network user can exploit this flaw by sending crafted requests to the vulnerable endpoints.
OpenCVE Enrichment