Description
WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently reset the password of any user, including administrator. WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files versions 3.1 - 3.1.1.4.1 are vulnerable.
Remediation
Update to plugin version 3.1.1.4.2 or latest
References
Related Vulnerabilities
WordPress Plugin Advanced Custom Fields (ACF) Multiple Security Bypass Vulnerabilities (5.10.2)
SharePoint CVE-2020-1295 Vulnerability (CVE-2020-1295)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-7831)
WordPress Other Vulnerability (CVE-2007-0106)
WordPress Plugin Visual Form Builder Cross-Site Scripting (2.8.4)