{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-14335/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:easy_digital_downloads:easy_digital_downloads:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-14335"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Easy Digital Downloads (\u003c= 3.6.9)"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","web-application","cve-2026-14335"],"_cs_type":"advisory","_cs_vendors":["Easy Digital Downloads"],"content_html":"\u003cp\u003eThe Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within its handling of PayPal Instant Payment Notification (IPN) parameters. This vulnerability affects all versions up to and including 3.6.9. An unauthenticated attacker can exploit this flaw by sending crafted requests containing malicious JavaScript to the plugin's IPN processing endpoint. When these payloads are successfully stored and later rendered in the browser of an administrator or other authenticated user, the script executes, potentially leading to session hijacking, unauthorized actions, or further compromise of the WordPress site. This vulnerability highlights the importance of rigorous input validation for third-party payment integration endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users' sessions. This can lead to the compromise of administrator accounts, unauthorized modification of site content, or the injection of malicious redirects. Given the widespread use of Easy Digital Downloads for e-commerce, this vulnerability poses a significant risk to the integrity and security of online storefronts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the Easy Digital Downloads plugin to the latest available version beyond 3.6.9 immediately.\u003c/li\u003e\n\u003cli\u003eAudit WordPress access logs for anomalous HTTP POST requests directed at payment notification endpoints that include script tags or common XSS payloads in query parameters.\u003c/li\u003e\n\u003cli\u003eImplement or enforce a strong Content Security Policy (CSP) to mitigate the impact of XSS by restricting the execution of unauthorized scripts.\u003c/li\u003e\n\u003cli\u003eReview administrative logs for unusual account modifications or unauthorized actions that may indicate successful session compromise via XSS.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T07:51:14Z","date_published":"2026-10-10T07:51:14Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-14335/","summary":"An unauthenticated stored XSS vulnerability in the Easy Digital Downloads WordPress plugin allows attackers to inject malicious scripts via PayPal IPN parameters.","title":"Stored Cross-Site Scripting Vulnerability in Easy Digital Downloads Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-14335/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-14335","version":"https://jsonfeed.org/version/1.1"}