Skip to main content

Vendor archive

awesomemotive CVEs

Beta · best-effort

64 CVEs tagged to vendor awesomemotive6 Critical, 6 High, 50 Medium, 2 Low, 0 Unrated.

CVE-2025-4670

Published May 29, 2025

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcod…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-2252

Published Mar 25, 2025

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2024-13517

Published Jan 18, 2025

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in all versions u…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12875

Published Dec 21, 2024

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 v…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9654

Published Dec 17, 2024

The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-40005

Published Dec 13, 2024

Missing Authorization vulnerability in Syed Balkhi Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-43162

Published Nov 1, 2024

Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: fr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2439

Published Sep 24, 2024

The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5057

Published Aug 29, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital D…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6692

Published Aug 12, 2024

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Ag…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-6691

Published Aug 12, 2024

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cu…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2302

Published Apr 9, 2024

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0659

Published Feb 5, 2024

The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing o…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51684

Published Feb 1, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Digital Downloads Easy Digital Downloads – Sell Digital Files (eCommerce…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-25095

Published Jan 8, 2024

The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-6114

Published Dec 26, 2023

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3081

Published Jul 12, 2023

The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitiz…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-33309

Published May 28, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-30869

Published May 2, 2023

Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-3600

Published Nov 21, 2022

The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-2387

Published Nov 7, 2022

The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2552

Published Aug 22, 2022

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and fu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2551

Published Aug 22, 2022

The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer sc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0707

Published Apr 18, 2022

The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 64 CVEsPage 1 of 3