The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated attackers to extract private post titles of downloads. The impact here is minimal.
Metrics
Affected Vendors & Products
References
History
Fri, 08 Aug 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Awesomemotive
Awesomemotive easy Digital Downloads |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Awesomemotive
Awesomemotive easy Digital Downloads |
Mon, 31 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Mar 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated attackers to extract private post titles of downloads. The impact here is minimal. | |
Title | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-25T07:04:54.606Z
Updated: 2025-03-31T17:44:11.737Z
Reserved: 2025-03-12T14:30:10.813Z
Link: CVE-2025-2252

Updated: 2025-03-31T17:43:49.523Z

Status : Analyzed
Published: 2025-03-25T07:15:38.337
Modified: 2025-08-08T19:21:17.160
Link: CVE-2025-2252

No data.