CVE-2015-9296: XSS
Published Aug 13, 2019
·Updated
The download-monitor plugin before 1.7.1 for WordPress has XSS related to addqueryarg.
Affected Software
1 affected component
Never5 Download Monitor Wordpress<1.7.1
Event History
Aug 13, 2019
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
Description
Frequently Asked Questions
1
What is CVE-2015-9296?
CVE-2015-9296 is a vulnerability in the download-monitor plugin for WordPress that allows for cross-site scripting (XSS) attacks.
2
How does CVE-2015-9296 impact WordPress websites?
CVE-2015-9296 allows attackers to inject malicious scripts into web pages, potentially leading to session hijacking, defacement, or stealing sensitive information.
3
What is the severity of CVE-2015-9296?
CVE-2015-9296 has a severity rating of medium (6.1 out of 10).
4
Which version of the download-monitor plugin is affected by CVE-2015-9296?
The download-monitor plugin before version 1.7.1 for WordPress is affected by CVE-2015-9296.
5
How can I fix CVE-2015-9296?
To fix CVE-2015-9296, update the download-monitor plugin to version 1.7.1 or newer.