Medium severity4.3NVD Advisory· Published Nov 7, 2022· Updated Jun 17, 2026
CVE-2022-2387
CVE-2022-2387
Description
The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:*Range: <3.0
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <3.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/db3c3c78-1724-4791-9ab6-ebb2e8a4c8b8nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.