CVE-2015-9365: XSS
Published Aug 28, 2019
·Updated
Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
1 affected component
iThemes Authorize.net Wordpress<1.1.0
Remediation
Event History
Aug 28, 2019
CVE Published
via MITRE·11:58 AM
Data Sourced
via MITRE·11:58 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2015-9365.
2
What is the severity of CVE-2015-9365?
The severity of CVE-2015-9365 is medium with a CVSS score of 6.1.
3
Which software is affected by CVE-2015-9365?
The Authorize.net Add-on for iThemes Exchange before version 1.1.0 for WordPress is affected by CVE-2015-9365.
4
How can the vulnerability CVE-2015-9365 be exploited?
CVE-2015-9365 can be exploited through XSS attacks using the add_query_arg() and remove_query_arg() functions.
5
Are there any references for CVE-2015-9365?
Yes, you can find more information about CVE-2015-9365 at the following links: [link1](https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html) and [link2](https://ithemes.com/coordinated-wordpress-plugin-security-update/).