The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious sites if they can successfully trick them into performing an action.
We have discovered 14,294 live websites that are affected by CVE-2025-14783.
| Product | |
| Category | Ecommerce |
| Vulnerable Domains | 14,294 live websites (99% of Easy Digital Downloads install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 146 versions ( 99% of all versions) |
| 7,061 websites | |
| 1,114 websites | |
| 972 websites | |
| 748 websites | |
| 556 websites | |
| 409 websites | |
| 374 websites | |
| 242 websites | |
| 229 websites | |
| 220 websites |
| .com | 8,736 websites |
| .org | 843 websites |
| .net | 468 websites |
| .co.uk | 344 websites |
| .de | 343 websites |
| .it | 253 websites |
| .fr | 167 websites |
| .com.au | 167 websites |
| .nl | 156 websites |
| .pl | 112 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | *,*** | ||
| ***************.eu | *,*** | ||
| **************.com | *,*** | ||
| **********.com | *,*** | ||
| ************.com | *,*** | ||
| *************.com | *,*** | ||
| **********.com | *,*** | ||
| *************.com | *,*** | ||
| *********.com | *,*** | ||
| *********.io | *,*** |
FAQ