A vulnerability was found in Easy Digital Downloads Plugin up to 3.3.8.1 on WordPress. It has been classified as problematic. Affected is the function edd_receipt of the component Shortcode Handler. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2025-4670. It is possible to launch the attack remotely. There is no exploit available.