CVE-2015-9362: XSS
Published Aug 28, 2019
·Updated
The Post Connector plugin before 1.0.4 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
1 affected component
Never5 Post Connector Wordpress<1.0.4
Event History
Aug 28, 2019
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2015-9362.
2
What is the severity level of CVE-2015-9362?
The severity level of CVE-2015-9362 is medium.
3
What is the affected software for CVE-2015-9362?
The affected software for CVE-2015-9362 is Never5 Post Connector plugin before 1.0.4 for WordPress.
4
How can the vulnerability be exploited?
The vulnerability can be exploited through XSS (Cross-Site Scripting) attacks using the add_query_arg() and remove_query_arg() functions.
5
Is there a fix available for CVE-2015-9362?
Yes, the fix for CVE-2015-9362 is to update the Post Connector plugin to version 1.0.4 or later.