Description
WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently reset the password of any user, including administrator. WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files versions 3.1 - 3.1.1.4.1 are vulnerable.
Remediation
Update to plugin version 3.1.1.4.2 or latest
References
Related Vulnerabilities
WordPress Plugin Cool Timeline (Horizontal & Vertical Timeline) Security Bypass (2.3.3)
Magento CVE-2020-9585 Vulnerability (CVE-2020-9585)
SharePoint Improper Input Validation Vulnerability (CVE-2020-1025)
WordPress 5.0.x Multiple Vulnerabilities (5.0 - 5.0.9)
Moodle Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-21809)