The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated attackers to extract private post titles of downloads. The impact here is minimal.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Mar 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated attackers to extract private post titles of downloads. The impact here is minimal. | |
Title | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-25T07:04:54.606Z
Updated: 2025-03-25T07:04:54.606Z
Reserved: 2025-03-12T14:30:10.813Z
Link: CVE-2025-2252

No data.

Status : Received
Published: 2025-03-25T07:15:38.337
Modified: 2025-03-25T07:15:38.337
Link: CVE-2025-2252

No data.