2.1
CVSSv2

CVE-2022-0706

Published: 18/04/2022 Updated: 25/04/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 187
Vector: AV:N/AC:H/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Easy Digital Downloads WordPress plugin prior to 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sandhillsdev easy digital downloads