What the vulnerability does
01Description
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
Explanation of Vulnerability in Simple Terms
Easy Digital Downloads versions up to 3.6.7 contain an authentication bypass vulnerability. An attacker can modify data or disrupt service without valid credentials. The vulnerability requires only network access and no user interaction. Site administrators should update to a version newer than 3.6.7 immediately.
What an attacker can do
Modify site data or cause service disruption without authentication.
Potential impact on your site
Unauthorized users can alter downloads, orders, or customer data, or cause the site to become unavailable.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities