← Back to browse · API

CVE-2023-23489

Severity
CRITICAL
CVSS
9.8
EPSS
0.11172
Risk score
43.11
CISA KEV
No
PoC
No
Published
2023-01-20
Modified
2025-04-03
First seen
2026-08-07
Aliases
EUVD-2023-27589, GHSA-7745-326P-VHM6
Products
n/a:Easy Digital Downloads WordPress Plugin < 3.1.0.4
Sources
euvd EUVD-2023-27589

Description

The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.

References