Sceawere
Vulnerability Detail
CVE-2026-105194UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Easy Digital Downloads Improper Authorization
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Easy Digital Downloads
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-08T06:16:39.763Z",
"pubdate": "2026-10-08T06:16:39.763Z",
"executiveSummary": "The Easy Digital Downloads WordPress plugin, in versions prior to 3.7.1, contains an improper authorization vulnerability. This security flaw allows authenticated users with subscriber-level privileges to bypass access controls and retrieve unauthorized order information.\nThe vulnerability manifests as an insecure direct object reference or insufficient server-side validation during the retrieval of block order data. By exploiting this flaw, a malicious actor can view order history belonging to other customers and extract cryptographically signed download links.\nThe impact is significant, as it enables unauthorized access to paid digital assets without requiring a legitimate transaction. This bypasses the plugin's primary revenue-protection mechanisms. The vulnerability is exploitable remotely by any authenticated user, requiring no elevated administrative privileges or complex preconditions beyond having a standard subscriber account on the affected WordPress installation.\nRisk implications include loss of revenue, unauthorized distribution of intellectual property, and potential violation of customer data privacy regulations. Immediate remediation is required to ensure that access control logic correctly validates ownership of order data before rendering content or generating download tokens.",
"technicalDetails": "The root cause of this vulnerability lies in an insufficient implementation of access control checks within the block-based order data retrieval mechanism of the Easy Digital Downloads plugin. Specifically, the API endpoints or server-side functions responsible for processing and returning order data fail to verify that the requesting user identity matches the user associated with the target order object.\nIn a secure configuration, the application should perform an ownership check by comparing the current session's User ID (UID) against the order owner's metadata stored in the database. In the vulnerable versions prior to 3.7.1, the system processes requests for order data without enforcing this identity correlation. Consequently, the application treats subscriber-level requests as trusted, permitting the retrieval of sensitive order details regardless of the resource's owner.\nThe exploitation flow proceeds as follows: First, an authenticated attacker initiates a request to the vulnerable endpoint responsible for rendering order blocks. The request includes parameters identifying specific order IDs or transaction references. Because the backend code omits the necessary ownership validation, it processes the request and fetches the order object from the database.\nThe attacker then receives an HTTP response containing private order data, which includes the product details associated with that transaction. Critically, the server also generates and returns signed download URLs. These URLs utilize the plugin's internal signing logic, which provides temporary or permanent access to paid files. By capturing these signed links, the attacker can download the digital files directly from the server, effectively bypassing the checkout and payment verification layers.\nBecause these signed links are functional independently of the current session, the attacker does not need to maintain an active state with the application to retrieve the files once the links are obtained. The exposure of these signed URLs effectively invalidates the authorization constraints designed to restrict access only to paying customers. The failure occurs in the API/AJAX handling layer of the plugin, where it incorrectly assumes that the request origin is intrinsically authorized to view order data if it relates to a block being rendered, ignoring the context of the user account requesting the data.\nPost-exploitation, the attacker gains full, unauthorized access to any digital product that has previously been ordered by legitimate customers, leading to a complete compromise of the plugin's access control integrity for paid digital content."
}