First published: Tue Aug 13 2019(Updated: )
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All In One WP Security & Firewall | <3.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9294 is a vulnerability found in the all-in-one-wp-security-and-firewall plugin before version 3.9.5 for WordPress.
The severity of CVE-2015-9294 is medium (6.1).
The affected software for CVE-2015-9294 is the all-in-one-wp-security-and-firewall plugin before version 3.9.5 for WordPress.
The CWE ID for CVE-2015-9294 is 79.
To fix CVE-2015-9294, update the all-in-one-wp-security-and-firewall plugin to version 3.9.5 or higher.