Sceawere
Vulnerability Detail
CVE-2026-14335UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Easy Digital Downloads
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2h ago
- Vendor
- smub
- Product
- Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T06:16:41.447Z",
"pubdate": "2026-10-10T06:16:41.447Z",
"executiveSummary": "Easy Digital Downloads for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) stemming from improper handling of PayPal Instant Payment Notification (IPN) parameters.\nThe vulnerability affects all versions up to and including 3.6.9.\nAn unauthenticated remote attacker can inject malicious JavaScript payloads via crafted IPN requests.\nUpon successful injection, these scripts execute within the context of an administrator's browser session when they view affected pages within the WordPress dashboard.\nThis vulnerability poses a significant risk, as successful exploitation could lead to unauthorized administrative actions, session hijacking, or the deployment of further malicious code, effectively compromising the integrity and security of the WordPress installation.\nNo authentication is required to initiate the attack, as the vulnerable endpoint is exposed to public-facing network requests.",
"technicalDetails": "The vulnerability originates from a failure to sanitize and validate input provided to the PayPal IPN listener within the Easy Digital Downloads plugin. The application processes incoming IPN data directly from the PayPal gateway without adequate defensive filtering or context-aware output encoding.\nThe root cause is identified as insufficient input sanitization of the parameters transmitted during the IPN handshake process. When the plugin processes these parameters, it fails to strip or escape active content, allowing for the persistence of malicious scripts within the database.\nThe attack flow begins when an attacker sends a crafted POST request mimicking a PayPal IPN notification to the plugin's listener URL. By embedding malicious JavaScript payloads into specific IPN parameters, the attacker forces the server to store the script in the plugin's logs or transaction history. Because the system does not properly escape these values upon output, the payload resides within the application's backend interface.\nWhen an authorized user, typically an administrator, navigates to the affected page in the WordPress dashboard (e.g., viewing transaction logs or plugin settings), the browser interprets the stored payload as legitimate code and executes it. This context-dependent execution allows the attacker to operate with the privileges of the victim.\nThe attack requires no prior authentication or administrative privileges, as the entry point is a public listener designed to interface with external payment gateways. The network exposure is absolute, as the endpoint must remain reachable by the PayPal infrastructure, making it inherently accessible to any actor capable of generating forged HTTP requests.\nPost-exploitation, the impact is severe. An attacker can leverage the victim's session to execute administrative commands, modify system settings, create new administrative users, or redirect users to malicious domains. The persistence of the XSS payload ensures that the attack remains viable until the malicious entries are manually identified and purged from the database, or the plugin's input handling logic is corrected to properly neutralize active content."
}