CVE-2025-14783

Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect

The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious sites if they can successfully trick them into performing an action.


We have discovered 8,335 live websites that are affected by CVE-2025-14783.

Run a Free Instant Scan




Affected Software

Product  Easy Digital Downloads
Category Ecommerce
Vulnerable Domains8,335 live websites (60% of Easy Digital Downloads install base)
Vulnerable Versions
  • from 0 through 3.6.2
Vulnerable Versions Count143 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-640 Weak Password Recovery Mechanism for Forgotten Password



Details

  • Published - Dec 31, 2025
  • Updated - Apr 8, 2026

Credits

  • Angus Girvan (finder)

Website Distribution by Country

Number of websites using CVE-2025-14783
United States3,742 websites



Iran713 websites
Germany648 websites
GB427 websites
France313 websites
Italy269 websites
Cyprus222 websites
Canada153 websites
Spain122 websites
Netherlands120 websites

Website Distribution by TLD

Number of websites using CVE-2025-14783
.com4,809 websites
.org439 websites
.net273 websites
.de204 websites
.it180 websites
.co.uk176 websites
.fr91 websites
.ru87 websites
.nl86 websites
.com.au85 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14783

Top websites that are affected by CVE-2025-14783. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.eu Netherlands*,***
**************.com Canada*,***
**********.com United States*,***
*********.com United States*,***
*********.com United States*,***
******.*********.com United States*,***
*************.com United States*,***
*********.com United States*,***
**********.com Australia**,***
***********.com United States**,***
See full domain list

FAQ

CVE-2025-14783 is Weak Password Recovery Mechanism for Forgotten Password in Easy Digital Downloads
A total of 8,335 websites have been identified as vulnerable to CVE-2025-14783, based on global website indexing conducted by WebTechSurvey.
The Easy Digital Downloads is affected by the CVE-2025-14783 vulnerability.
Easy Digital Downloads versions up to and including 3.6.2 are vulnerable to CVE-2025-14783.