CVE-2015-9363: XSS
Published Aug 28, 2019
·Updated
iThemes Exchange before 1.12.0 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
1 affected component
iThemes Exchange Wordpress<1.12.0
Remediation
Event History
Aug 28, 2019
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
Description
Frequently Asked Questions
1
What is CVE-2015-9363?
CVE-2015-9363 is a vulnerability found in iThemes Exchange before version 1.12.0 for WordPress, which allows for XSS attacks.
2
What is XSS?
XSS stands for Cross-Site Scripting, which is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
3
How does CVE-2015-9363 affect iThemes Exchange for WordPress?
CVE-2015-9363 affects iThemes Exchange before version 1.12.0 for WordPress by enabling XSS attacks through the add_query_arg() and remove_query_arg() functions.
4
What is the severity of CVE-2015-9363?
The severity of CVE-2015-9363 is rated as medium with a CVSS severity score of 6.1.
5
How can I fix CVE-2015-9363 in iThemes Exchange for WordPress?
To fix CVE-2015-9363, upgrade iThemes Exchange to version 1.12.0 or later, as this vulnerability has been patched in that version.