CVE-2015-9371: XSS
Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9371?
CVE-2015-9371 is a vulnerability in the Manual Purchases Add-on for iThemes Exchange before version 1.1.0 for WordPress that allows for XSS attacks.
How severe is CVE-2015-9371?
CVE-2015-9371 has a severity score of 6.1 (medium).
What software is affected by CVE-2015-9371?
The Manual Purchases Add-on for iThemes Exchange before version 1.1.0 for WordPress is affected by CVE-2015-9371.
How can I fix CVE-2015-9371?
To fix CVE-2015-9371, you should update Manual Purchases Add-on for iThemes Exchange to version 1.1.0 or higher.
Where can I find more information about CVE-2015-9371?
You can find more information about CVE-2015-9371 at the following references: [Link 1](https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html), [Link 2](https://ithemes.com/coordinated-wordpress-plugin-security-update/).