Medium severity4.8NVD Advisory· Published Oct 21, 2021· Updated Jun 17, 2026
CVE-2021-39354
CVE-2021-39354
Description
The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:*Range: <=2.11.2
- Range: <=2.11.2
- Easy Digital Downloads/Easy Digital Downloadsv5Range: 2.11.2
Patches
Vulnerability mechanics
References
3- plugins.trac.wordpress.org/changeset/2616149/easy-digital-downloads/trunk/includes/admin/payments/class-payments-table.phpnvdPatchThird Party Advisory
- github.com/BigTiger2020/word-press/blob/main/Easy%20Digital%20Downloads.mdnvdExploitThird Party Advisory
- www.wordfence.com/vulnerability-advisories/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.