Description
WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions. WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files version 2.9.16 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.9.17 or latest
References
Related Vulnerabilities
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-16862)
Oracle Database Server Other Vulnerability (CVE-2001-1041)
Moodle CVE-2022-40314 Vulnerability (CVE-2022-40314)
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-34429)
WordPress Plugin Premium Addons for Elementor Multiple Cross-Site Scripting Vulnerabilities (4.2.7)