CVE-2025-14783

Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect

The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious sites if they can successfully trick them into performing an action.


We have discovered 14,294 live websites that are affected by CVE-2025-14783.

Run a Free Instant Scan




Affected Software

Product  Easy Digital Downloads
Category Ecommerce
Vulnerable Domains14,294 live websites (99% of Easy Digital Downloads install base)
Vulnerable Versions
  • from 0 through 3.6.2
Vulnerable Versions Count146 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-640 Weak Password Recovery Mechanism for Forgotten Password



Details

  • Published - Dec 31, 2025
  • Updated - Dec 31, 2025

Credits

  • Angus Girvan (finder)

Website Distribution by Country

Number of websites using CVE-2025-14783
United States7,061 websites



Germany1,114 websites
Iran972 websites
GB748 websites
France556 websites
Italy409 websites
Cyprus374 websites
Canada242 websites
Japan229 websites
Australia220 websites

Website Distribution by TLD

Number of websites using CVE-2025-14783
.com8,736 websites
.org843 websites
.net468 websites
.co.uk344 websites
.de343 websites
.it253 websites
.fr167 websites
.com.au167 websites
.nl156 websites
.pl112 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14783

Top websites that are affected by CVE-2025-14783. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
***************.eu Netherlands*,***
**************.com Canada*,***
**********.com United States*,***
************.com United States*,***
*************.com United States*,***
**********.com United States*,***
*************.com United States*,***
*********.com United States*,***
*********.io Netherlands*,***
See full domain list

FAQ

CVE-2025-14783 is Weak Password Recovery Mechanism for Forgotten Password in Easy Digital Downloads
A total of 14,294 websites have been identified as vulnerable to CVE-2025-14783, based on global website indexing conducted by WebTechSurvey.
The Easy Digital Downloads is affected by the CVE-2025-14783 vulnerability.
Easy Digital Downloads versions up to and including 3.6.2 are vulnerable to CVE-2025-14783.