First published: Wed Aug 28 2019(Updated: )
Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ithemes Easy Canadian Sales Taxes | <1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9367 is a Cross-Site Scripting (XSS) vulnerability in the Easy Canadian Sales Taxes Add-on for iThemes Exchange plugin before version 1.1.0 for WordPress.
CVE-2015-9367 affects the Easy Canadian Sales Taxes Add-on for iThemes Exchange plugin before version 1.1.0, allowing an attacker to perform Cross-Site Scripting attacks.
CVE-2015-9367 has a severity score of 6.1 (medium) according to the Common Vulnerability Scoring System (CVSS).
To fix CVE-2015-9367, you should update the Easy Canadian Sales Taxes Add-on for iThemes Exchange plugin to version 1.1.0 or later.
You can find more information about CVE-2015-9367 in the following references: [1] https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html, [2] https://ithemes.com/coordinated-wordpress-plugin-security-update/