CVE-2024-6691

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Currency Settings

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the currency value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.


We have discovered 7,312 live websites that are affected by CVE-2024-6691.

Test my site




Affected Software

Product  Easy Digital Downloads
Category Ecommerce
Vulnerable Domains7,312 live websites (43.87% of Easy Digital Downloads install base)
Vulnerable Versions
  • from 0 through 3.3.2
Vulnerable Versions Count158 versions ( 95.18% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 10, 2024
  • Updated - Aug 12, 2024

Credits

  • Jonas Benjamin Friedli (finder)

CVE-2024-6691 usage by Country

United States3,393 websites



Germany719 websites
Iran501 websites
France355 websites
GB328 websites
Japan170 websites
Cyprus149 websites
Italy142 websites
Poland139 websites
Canada105 websites

CVE-2024-6691 usage by TLD

.com4,153 websites
.org363 websites
.net260 websites
.de184 websites
.co.uk179 websites
.pl119 websites
.it115 websites
.fr90 websites
.com.au90 websites
.ru71 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-6691

Top websites that are affected by CVE-2024-6691. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
***************.eu Netherlands*,***
**********.com United States*,***
************.com United States*,***
*************.com United States*,***
*********.com United States*,***
*********.com United States*,***
******.*********.com United States*,***
*************.com United States*,***
**************.net United States**,***
See full domain list

FAQ

CVE-2024-6691 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Easy Digital Downloads
A total of 7,312 websites have been identified as vulnerable to CVE-2024-6691, discovered through global website indexing conducted by WebTechSurvey.
Easy Digital Downloads is susceptible to CVE-2024-6691 vulnerability.
Easy Digital Downloads versions before, and including, 3.3.2 are vulnerable to CVE-2024-6691.