The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious sites if they can successfully trick them into performing an action.
We have discovered 8,335 live websites that are affected by CVE-2025-14783.
| Product | |
| Category | Ecommerce |
| Vulnerable Domains | 8,335 live websites (60% of Easy Digital Downloads install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 143 versions ( 97% of all versions) |
| 3,742 websites | |
| 713 websites | |
| 648 websites | |
| 427 websites | |
| 313 websites | |
| 269 websites | |
| 222 websites | |
| 153 websites | |
| 122 websites | |
| 120 websites |
| .com | 4,809 websites |
| .org | 439 websites |
| .net | 273 websites |
| .de | 204 websites |
| .it | 180 websites |
| .co.uk | 176 websites |
| .fr | 91 websites |
| .ru | 87 websites |
| .nl | 86 websites |
| .com.au | 85 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.eu | *,*** | ||
| **************.com | *,*** | ||
| **********.com | *,*** | ||
| *********.com | *,*** | ||
| *********.com | *,*** | ||
| ******.*********.com | *,*** | ||
| *************.com | *,*** | ||
| *********.com | *,*** | ||
| **********.com | **,*** | ||
| ***********.com | **,*** |
FAQ