Description
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
Published: 2026-07-27
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Easy Digital Downloads plugin version 3.6.9 and earlier contains an arbitrary file deletion flaw tied to insufficient path validation (CWE‑22). Based on the description, it is inferred that an authenticated administrator can delete any file on the server that is accessible through the plugin’s file handling routines, potentially removing core WordPress files, site themes, plugins, or configuration files. Based on the description, it is inferred that this loss of files can disrupt site operation and compromise availability, and may indirectly affect confidentiality if sensitive data is removed.

Affected Systems

The vulnerability affects the WordPress Easy Digital Downloads plugin from Syed Balkhi, versions 3.6.9 and earlier. Based on the description, it is inferred that any WordPress installation that has this plugin installed and is managed by an administrator with access to the plugin’s file deletion features is impacted.

Risk and Exploitability

The CVSS score of 4.9 indicates medium severity. EPSS score of 0.00325 (<1%) indicates a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires admin credentials or an ability to trigger the deletion function through the plugin interface, so it is unlikely to be remotely exploitable by unauthenticated users. Administrators should treat the flaw as a medium‑risk local privilege issue that could degrade site availability.

Generated by OpenCVE AI on August 3, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy Digital Downloads to the latest available version (≥3.7) to incorporate the fix.
  • If an upgrade is not possible, disable or remove the plugin to eliminate the deletion functionality.
  • Restrict file system permissions for the web server to the minimum necessary and monitor file system changes for unauthorized deletions.

Generated by OpenCVE AI on August 3, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Syed Balkhi
Syed Balkhi easy Digital Downloads
Wordpress
Wordpress wordpress
Vendors & Products Syed Balkhi
Syed Balkhi easy Digital Downloads
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
Title WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Syed Balkhi Easy Digital Downloads
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:17:23.498Z

Reserved: 2026-07-27T09:50:27.375Z

Link: CVE-2026-66476

cve-icon Vulnrichment

Updated: 2026-07-27T15:12:42.537Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:12.090

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-66476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')