CVE-2015-5532: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to adminpages/membershiplevels.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5532?
CVE-2015-5532 is classified as a medium-severity vulnerability due to its potential for remote exploitation through XSS attacks.
How do I fix CVE-2015-5532?
To fix CVE-2015-5532, update the Paid Memberships Pro plugin to version 1.8.4.3 or later.
What types of vulnerabilities does CVE-2015-5532 contain?
CVE-2015-5532 contains multiple cross-site scripting (XSS) vulnerabilities affecting several admin pages in the Paid Memberships Pro plugin.
Who is affected by CVE-2015-5532?
Users of the Paid Memberships Pro plugin for WordPress versions prior to 1.8.4.3 are affected by CVE-2015-5532.
What components are involved in CVE-2015-5532?
CVE-2015-5532 involves vulnerabilities in the membershiplevels.php, memberslist.php, and orders.php files within the adminpages directory.