CVE-2026-105194

Published: Ott 08, 2026 Last Modified: Ott 08, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase.

https://wpscan.com/vulnerability/aa49b193-8409-436f-a034-70b166afc483/