CVE-2015-9348: Codepeople Sell Downloads

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.

Affected products

  • Codepeople Sell Downloads: before 1.0.8 (fixed in 1.0.8)

Published 2019-08-27. Last modified 2026-06-17.