Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.7.1 - Unauthenticated Order Completion Without Confirmed Payment via Square Checkout

Low 3.7 CWE-841Fixed in 3.7.1.1
ID
WPSEC-2026-0605
Plugin
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy (easy-digital-downloads)
Affected
from 3.4.0 before 3.7.1.1
Remediation
Update to 3.7.1.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-841
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy on WPSec AttackSurface
Fix released
Published

Description

The Easy Digital Downloads plugin for WordPress is vulnerable to order completion without confirmed payment in versions 3.4.0 up to, and including, 3.7.1 when the Square payment gateway is connected and enabled. This is due to the Square checkout handler marking the order and its transaction as complete as soon as Square accepts the payment request, without checking that the returned payment's status is COMPLETED. This makes it possible for unauthenticated attackers, such as guest buyers whose Square payment is accepted but not yet completed (for example, a payment that remains pending), to receive a completed order, including the purchase receipt and download access, before the payment has settled, and to keep it if the payment never completes.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0