First published: Wed Aug 28 2019(Updated: )
The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <2015.0514 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9358 is classified as a medium severity vulnerability due to its ability to allow XSS attacks.
To fix CVE-2015-9358, update the FeedWordPress plugin to version 2015.0514 or later.
CVE-2015-9358 affects versions of the FeedWordPress plugin prior to 2015.0514.
CVE-2015-9358 can lead to cross-site scripting (XSS), potentially allowing attackers to inject malicious scripts into your site.
Website administrators and plugin developers are responsible for addressing CVE-2015-9358 by applying the necessary updates.