Impact
The Easy Digital Downloads plugin version 3.6.9 and earlier contains an arbitrary file deletion flaw tied to insufficient path validation (CWE‑22). Based on the description, it is inferred that an authenticated administrator can delete any file on the server that is accessible through the plugin’s file handling routines, potentially removing core WordPress files, site themes, plugins, or configuration files. Based on the description, it is inferred that this loss of files can disrupt site operation and compromise availability, and may indirectly affect confidentiality if sensitive data is removed.
Affected Systems
The vulnerability affects the WordPress Easy Digital Downloads plugin from Syed Balkhi, versions 3.6.9 and earlier. Based on the description, it is inferred that any WordPress installation that has this plugin installed and is managed by an administrator with access to the plugin’s file deletion features is impacted.
Risk and Exploitability
The CVSS score of 4.9 indicates medium severity. EPSS score of 0.00325 (<1%) indicates a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires admin credentials or an ability to trigger the deletion function through the plugin interface, so it is unlikely to be remotely exploitable by unauthenticated users. Administrators should treat the flaw as a medium‑risk local privilege issue that could degrade site availability.
OpenCVE Enrichment