Description
WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently reset the password of any user, including administrator. WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files versions 3.1 - 3.1.1.4.1 are vulnerable.
Remediation
Update to plugin version 3.1.1.4.2 or latest
References
Related Vulnerabilities
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker SQL Injection (7.1.11)
WordPress CVE-2019-17673 Vulnerability (CVE-2019-17673)
Drupal Core 7.x Remote Code Execution (7.0 - 7.73)
Grafana Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-13379)
WordPress Plugin Resize Image After Upload Cross-Site Request Forgery (1.8.5)