Review
Easy Digital Downloads
CVE published 2026-10-08
CVE-2026-105194
CVE-2026-105194 debrief based on CVE Program and NVD records. The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase. This vulnerability impacts defenders responsibl [truncated]