CVE-2015-9359: XSS
Published Aug 28, 2019
·Updated
The Jetpack plugin before 3.4.3 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
1 affected component
Automattic Jetpack Wordpress<3.4.3
Event History
Aug 28, 2019
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2015-9359.
2
What is the severity of CVE-2015-9359?
The severity of CVE-2015-9359 is medium.
3
What is the affected software?
The affected software is the Jetpack plugin before version 3.4.3 for WordPress.
4
What is the root cause of this vulnerability?
The root cause of this vulnerability is XSS (Cross-Site Scripting) via add_query_arg() and remove_query_arg() functions.
5
How can I fix CVE-2015-9359?
To fix CVE-2015-9359, update the Jetpack plugin to version 3.4.3 or newer.