CVE-2022-2387 Information

Description

The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history and does not ensure that the post to be deleted is actually a payment history. As a result attackers could make a logged in admin delete arbitrary post via a CSRF attack

Reference

https://wpscan.com/vulnerability/db3c3c78-1724-4791-9ab6-ebb2e8a4c8b8

Share on: