<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:easy_digital_downloads:easy_digital_downloads:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aeasy_digital_downloadseasy_digital_downloads/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:51:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aeasy_digital_downloadseasy_digital_downloads/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting Vulnerability in Easy Digital Downloads Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-14335/</link><pubDate>Sat, 10 Oct 2026 07:51:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-14335/</guid><description>An unauthenticated stored XSS vulnerability in the Easy Digital Downloads WordPress plugin allows attackers to inject malicious scripts via PayPal IPN parameters.</description><content:encoded><![CDATA[<p>The Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within its handling of PayPal Instant Payment Notification (IPN) parameters. This vulnerability affects all versions up to and including 3.6.9. An unauthenticated attacker can exploit this flaw by sending crafted requests containing malicious JavaScript to the plugin's IPN processing endpoint. When these payloads are successfully stored and later rendered in the browser of an administrator or other authenticated user, the script executes, potentially leading to session hijacking, unauthorized actions, or further compromise of the WordPress site. This vulnerability highlights the importance of rigorous input validation for third-party payment integration endpoints.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users' sessions. This can lead to the compromise of administrator accounts, unauthorized modification of site content, or the injection of malicious redirects. Given the widespread use of Easy Digital Downloads for e-commerce, this vulnerability poses a significant risk to the integrity and security of online storefronts.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering and security teams:</p>
<ul>
<li>Patch the Easy Digital Downloads plugin to the latest available version beyond 3.6.9 immediately.</li>
<li>Audit WordPress access logs for anomalous HTTP POST requests directed at payment notification endpoints that include script tags or common XSS payloads in query parameters.</li>
<li>Implement or enforce a strong Content Security Policy (CSP) to mitigate the impact of XSS by restricting the execution of unauthorized scripts.</li>
<li>Review administrative logs for unusual account modifications or unauthorized actions that may indicate successful session compromise via XSS.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>xss</category><category>web-application</category><category>cve-2026-14335</category></item></channel></rss>