PatchSiren

Easy Digital Downloads CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Easy Digital Downloads CVE published 2026-10-08

CVE-2026-105194

CVE-2026-105194 debrief based on CVE Program and NVD records. The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase. This vulnerability impacts defenders responsibl [truncated]