CVE-2015-9372: XSS
Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9372?
CVE-2015-9372 is a vulnerability in the Membership Add-on for iThemes Exchange plugin for WordPress that allows for cross-site scripting (XSS) attacks.
How does CVE-2015-9372 affect WordPress websites?
CVE-2015-9372 affects WordPress websites that have the Membership Add-on for iThemes Exchange plugin installed and running a version before 1.3.0.
What is the severity of CVE-2015-9372?
CVE-2015-9372 has a severity rating of medium, with a CVSS score of 6.1.
How can I fix CVE-2015-9372?
To fix CVE-2015-9372, users should update the Membership Add-on for iThemes Exchange plugin to version 1.3.0 or later.
Are there any additional resources on CVE-2015-9372?
Yes, you can refer to the following resources for more information on CVE-2015-9372: - [Sucuri Blog](https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html) - [iThemes Security Advisory](https://ithemes.com/coordinated-wordpress-plugin-security-update/)