CVE-2015-9367: XSS
Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-9367?
CVE-2015-9367 is a Cross-Site Scripting (XSS) vulnerability in the Easy Canadian Sales Taxes Add-on for iThemes Exchange plugin before version 1.1.0 for WordPress.
How does CVE-2015-9367 affect the Easy Canadian Sales Taxes Add-on?
CVE-2015-9367 affects the Easy Canadian Sales Taxes Add-on for iThemes Exchange plugin before version 1.1.0, allowing an attacker to perform Cross-Site Scripting attacks.
What is the severity of CVE-2015-9367?
CVE-2015-9367 has a severity score of 6.1 (medium) according to the Common Vulnerability Scoring System (CVSS).
How can I fix CVE-2015-9367?
To fix CVE-2015-9367, you should update the Easy Canadian Sales Taxes Add-on for iThemes Exchange plugin to version 1.1.0 or later.
Where can I find more information about CVE-2015-9367?
You can find more information about CVE-2015-9367 in the following references: [1] https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html, [2] https://ithemes.com/coordinated-wordpress-plugin-security-update/