CVE-2021-39354


Easy Digital Downloads <= 2.11.2 Authenticated Reflected Cross-Site Scripting

The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.



We have discovered 52 live websites that are affected by CVE-2021-39354.

Contact us to get more info




Affected Software

Product  Easy Digital Downloads
Category Ecommerce
Vulnerable Versions
  • from 2.11.2 through 2.11.2
Total Vulnerable Versions168
Vulnerable Domains52 live websites (0.28% of Easy Digital Downloads install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2021-39354 and the relative popularity of websites


Details

  • Published - Oct 21, 2021
  • Updated - Oct 22, 2021

Credits

  • Thinkland Security Team





Countries

United States31 websites



France5 websites
Australia2 websites
Germany2 websites
Iran2 websites
Italy2 websites
Canada1 websites
Cyprus1 websites
GB1 websites
India1 websites

TLDs

.com38 websites
.net3 websites
.com.au2 websites
.ca1 websites
.fr1 websites
.io1 websites
.it1 websites
.org1 websites
.ru1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2021-39354 through included software libraries and plugins.



References


Websites affected by CVE-2021-39354

Top websites that are affected by CVE-2021-39354. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
**************.com United States**,***
*****.com United States**,***
*************.com United States**,***
***********.com United States***,***
***********.com United States***,***
******.org United States*,***,***
************.com United States*,***,***
***.*****.com United States*,***,***
********.com United States*,***,***
**************.com United States*,***,***
See full domain list