Last night a crucial security flaw was discovered in the checkout process of Easy Digital Downloads and fixed immediately. Version 188.8.131.52 was pushed out and takes care of the issue. Please update immediately if you are on less than 184.108.40.206.
Due to the nature of the flaw, I cannot go into detail about exactly what the flaw was or how it could be exploited, but it had to do with user accounts and it was severe. The flaw permitted an experienced user who knew exactly what they were doing (and knew how to exploit the issue) to potentially gain admin access to sites running specific versions of EDD with specific configurations.
EDD versions affected: 1.4.2 – 220.127.116.11.
Version 18.104.22.168 fixes the problem
The flaw was discovered by Adam of Mint Themes, who, thankfully, reported it immediately, allowing us to send out a patch within 30 minutes of the discovery.