First published: Tue Aug 13 2019(Updated: )
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WPChill Download Monitor | <1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9296 is a vulnerability in the download-monitor plugin for WordPress that allows for cross-site scripting (XSS) attacks.
CVE-2015-9296 allows attackers to inject malicious scripts into web pages, potentially leading to session hijacking, defacement, or stealing sensitive information.
CVE-2015-9296 has a severity rating of medium (6.1 out of 10).
The download-monitor plugin before version 1.7.1 for WordPress is affected by CVE-2015-9296.
To fix CVE-2015-9296, update the download-monitor plugin to version 1.7.1 or newer.