CVE-2024-9654

Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass

The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the intended recipient of the purchase receipt. This makes it possible for unauthenticated attackers to bypass intended security restrictions and view the receipts of other users, which contains a link to download paid content. Successful exploitation requires knowledge of another customers email address as well as the file ID of the content they purchased.


We have discovered 1,675 live websites that are affected by CVE-2024-9654.

Run a Free Instant Scan




Affected Software

Product  Easy Digital Downloads
Category Ecommerce
Vulnerable Domains1,675 live websites (12% of Easy Digital Downloads install base)
Vulnerable Versions
  • from 3.1 through 3.3.4
Vulnerable Versions Count34 versions ( 23% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Dec 17, 2024
  • Updated - Dec 17, 2024

Credits

  • Arkadiusz Hydzik (finder)

Website Distribution by Country

Number of websites using CVE-2024-9654
United States670 websites



Germany154 websites
Iran131 websites
GB85 websites
France73 websites
Italy68 websites
Cyprus38 websites
Canada34 websites
Spain34 websites

Website Distribution by TLD

Number of websites using CVE-2024-9654
.com941 websites
.org85 websites
.net53 websites
.it49 websites
.co.uk43 websites
.de35 websites
.fr23 websites
.pl16 websites
.ca14 websites
.eu14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-9654

Top websites that are affected by CVE-2024-9654. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com United States*,***
*********.com United States*,***
**********.com Australia**,***
************.com United States**,***
*************.com United States**,***
************.com United States**,***
**********.com United States**,***
**************.com United States**,***
******.com United States**,***
*********.com United States**,***
See full domain list

FAQ

CVE-2024-9654 is Incorrect Authorization in Easy Digital Downloads
A total of 1,675 websites have been identified as vulnerable to CVE-2024-9654, based on global website indexing conducted by WebTechSurvey.
The Easy Digital Downloads is affected by the CVE-2024-9654 vulnerability.
Easy Digital Downloads versions up to and including 3.3.4 are vulnerable to CVE-2024-9654.