CVE 4.3 MEDIUM

Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect_CVE-2025-14783

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious sites if they can successfully trick them into performing an action.

Basic Information

ID CVE-2025-14783
Source Wordfence
Published Dec 31, 2025 at 06:24

Affected Product

Vendor smub
Product Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
Version *
Affected Versions smub Easy Digital Downloads – eCommerce Payments and Subscriptions made easy *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.