CVE-2015-9324: SQL Injection
Published Aug 16, 2019
·Updated
The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
Affected Software
2 affected components
Sandhillsdev Easy Digital Downloads Wordpress<2.3.3
Awesomemotive Easy Digital Downloads Wordpress<2.3.3
Event History
Aug 16, 2019
CVE Published
via MITRE·08:10 PM
Data Sourced
via MITRE·08:10 PM
Description
Frequently Asked Questions
1
What is CVE-2015-9324?
CVE-2015-9324 is a vulnerability in the easy-digital-downloads plugin for WordPress that allows SQL injection.
2
How severe is CVE-2015-9324?
CVE-2015-9324 is considered critical with a severity rating of 9.8 out of 10.
3
How does CVE-2015-9324 affect the easy-digital-downloads plugin?
CVE-2015-9324 affects the easy-digital-downloads plugin versions prior to 2.3.3 and allows SQL injection.
4
How can I fix CVE-2015-9324?
To fix CVE-2015-9324, update your easy-digital-downloads plugin to version 2.3.3 or later.
5
Where can I find more information about CVE-2015-9324?
You can find more information about CVE-2015-9324 on the official WordPress plugin website and the WPScan Vulnerability Database.