Vulnerability in Easy Digital Downloads – eCommerce Payments and Subscriptions made easy — CVE-2026-105194
MediumSeverity
0.2%Estimated exploit probability
40,000+ sitesInstalls
3.7.1Fixed in
What to do now
Update Easy Digital Downloads – eCommerce Payments and Subscriptions made easy to 3.7.1 or later.
Affected versions
- Everything before 3.7.1
Affected: Easy Digital Downloads – eCommerce Payments and Subscriptions made easy (plugin, easy-digital-downloads)
What the vulnerability is
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 3.7.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.