---
id: CVE-2026-105194
title: >-
  The Easy Digital Downloads  WordPress plugin before 3.7.1 does not restrict a
  block's order data to the current user, allowing users with subscriber-level
  access to view other customers' recent order products and obtain signed
  download l…
summary: >-
  The Easy Digital Downloads  WordPress plugin before 3.7.1 does not restrict a
  block's order data to the current user, allowing users with subscriber-level
  access to view other customers' recent order products and obtain signed
  download l…
severity: none
cwe:
  - CWE-200
product: Easy Digital Downloads
affected:
  - easy_digital_downloads < 3.7.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T06:16:39.763'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105194'
references:
  - url: 'https://wpscan.com/vulnerability/aa49b193-8409-436f-a034-70b166afc483/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T07:18:54.838Z'
---

## Overview

The Easy Digital Downloads  WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
