CVE-2023-30869


WordPress Easy Digital Downloads Plugin 3.1-3.1.1.4.1 is vulnerable to Privilege Escalation

Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.



We have discovered 1,068 live websites that are affected by CVE-2023-30869.

Contact us to get more info




Affected Software

Product  Easy Digital Downloads
Category Ecommerce
Vulnerable Versions
  • from 3.1 through 3.1.1.4.1
Total Vulnerable Versions168
Vulnerable Domains1,068 live websites (5.71% of Easy Digital Downloads install base)


Common Weakness Enumeration


CWE-287 Improper Authentication


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-30869 and the relative popularity of websites


Details

  • Published - May 2, 2023
  • Updated - May 3, 2023

Credits

  • Tien Nguyen Anh (Patchstack Alliance) (finder)





Countries

United States484 websites



Iran84 websites
Germany50 websites
GB49 websites
Italy43 websites
France43 websites
35 websites
Canada27 websites
Cyprus22 websites
Australia21 websites

TLDs

.com589 websites
.org76 websites
.net48 websites
.it28 websites
.de20 websites
.co.uk18 websites
.ca15 websites
.com.au14 websites
.fr12 websites
.nl10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-30869 through included software libraries and plugins.



References


Websites affected by CVE-2023-30869

Top websites that are affected by CVE-2023-30869. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
********.com United States*,***
*************.com United States*,***
**********.com United States**,***
************.com United States**,***
*****************.com United States**,***
********.net United States**,***
***.***********.com United States**,***
*****.org United States**,***
********.co Germany**,***
***********.com United States**,***
See full domain list