CVE-2015-9348: Codepeople Sell Downloads
High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
Affected products
- Codepeople Sell Downloads: before 1.0.8 (fixed in 1.0.8)
Published 2019-08-27. Last modified 2026-06-17.