CVE-2025-11271 | Easy Digital Downloads Plugin up to 3.5.2 on WordPress Transaction ID reliance on untrusted inputs in a security decision (EUVD-2025-37973 / CNNVD-202511-697)
A vulnerability labeled as critical has been found in Easy Digital Downloads Plugin up to 3.5.2 on WordPress. This affects an unknown function of the component Transaction ID Handler. Executing manipulation can lead to reliance on untrusted inputs in a security decision.
This vulnerability is handled as CVE-2025-11271. The attack can be executed remotely. There is not any exploit available.