CVE-2025-11271
Last modified
CVE-2025-11271 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. Because this value is attacker-supplied, an unauthenticated actor can submit a forged IPN and have it treated as verified, even on production sites and with verification otherwise enabled. A valid PayPal transaction id is needed, restricting order manipulation to orders placed by the attacker. This, in turn, requires them to have a customer account.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-11271?
How severe is CVE-2025-11271?
How do I fix CVE-2025-11271?
Are you affected by CVE-2025-11271?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
