CVE-2015-9369: XSS
Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-9369?
CVE-2015-9369 is a vulnerability in the Easy US Sales Taxes Add-on for iThemes Exchange plugin for WordPress, which allows for cross-site scripting (XSS) attacks.
How does CVE-2015-9369 affect iThemes Exchange?
CVE-2015-9369 affects iThemes Exchange before version 1.1.0 and allows attackers to execute malicious scripts through the add_query_arg() and remove_query_arg() functions.
What is the severity level of CVE-2015-9369?
CVE-2015-9369 has a severity level of medium with a CVSS score of 6.1.
How can I fix CVE-2015-9369 in iThemes Exchange?
To fix CVE-2015-9369, it is recommended to update the Easy US Sales Taxes Add-on for iThemes Exchange plugin to version 1.1.0 or later.
Where can I find more information about CVE-2015-9369?
More information about CVE-2015-9369 can be found at the following references: [link1](https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html), [link2](https://ithemes.com/coordinated-wordpress-plugin-security-update/).