CVE-2015-9348: Input Validation
Published Aug 27, 2019
·Updated
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
Affected Software
1 affected component
CodePeople Sell Downloads Wordpress<1.0.8
Event History
Aug 27, 2019
CVE Published
via MITRE·12:21 PM
Data Sourced
via MITRE·12:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9348?
CVE-2015-9348 has a medium severity rating due to its potential for brute-force attacks.
2
How do I fix CVE-2015-9348?
To fix CVE-2015-9348, update the Sell Downloads plugin to version 1.0.8 or later.
3
What impact does CVE-2015-9348 have on my WordPress site?
CVE-2015-9348 allows unauthorized users to guess purchase IDs, compromising account security.
4
Is my WordPress website vulnerable to CVE-2015-9348?
If you are using a version of the Sell Downloads plugin prior to 1.0.8, your site is vulnerable to CVE-2015-9348.
5
Who is affected by CVE-2015-9348?
Users of the Sell Downloads plugin for WordPress prior to version 1.0.8 are affected by CVE-2015-9348.