{
 "id": "WPSEC-2026-0605",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0605/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0605/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0605/index.md",
 "title": "Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.7.1 - Unauthenticated Order Completion Without Confirmed Payment via Square Checkout",
 "description": "The Easy Digital Downloads plugin for WordPress is vulnerable to order completion without confirmed payment in versions 3.4.0 up to, and including, 3.7.1 when the Square payment gateway is connected and enabled. This is due to the Square checkout handler marking the order and its transaction as complete as soon as Square accepts the payment request, without checking that the returned payment's status is COMPLETED. This makes it possible for unauthenticated attackers, such as guest buyers whose Square payment is accepted but not yet completed (for example, a payment that remains pending), to receive a completed order, including the purchase receipt and download access, before the payment has settled, and to keep it if the payment never completes.",
 "plugin": {
  "slug": "easy-digital-downloads",
  "name": "Easy Digital Downloads – eCommerce Payments and Subscriptions made easy",
  "full_name": "Easy Digital Downloads – eCommerce Payments and Subscriptions made easy",
  "wordpress_org": "https://wordpress.org/plugins/easy-digital-downloads/",
  "advisories_url": "https://wpsec.com/vuln/plugin/easy-digital-downloads/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/easy-digital-downloads"
 },
 "type": "BYPASS",
 "cwe": [
  "CWE-841"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": "3.4.0",
    "from_inclusive": true,
    "to": "3.7.1.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 3.4.0 before 3.7.1.1"
  ]
 },
 "introduced_in": "3.4.0",
 "fixed_in": "3.7.1.1",
 "remediation": "Update to 3.7.1.1 or later.",
 "fix_released": "2026-10-06T21:48:25+00:00",
 "published": "2026-10-07T22:44:38+00:00",
 "updated": "2026-10-07T11:22:51.611173+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0605/",
  "https://plugins.svn.wordpress.org/easy-digital-downloads/tags/3.7.1.1/",
  "https://wordpress.org/plugins/easy-digital-downloads/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/easy-digital-downloads",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}