First published: Wed Aug 28 2019(Updated: )
PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iThemes PayPal Pro | <1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9373 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting (XSS).
To remediate CVE-2015-9373, update the iThemes PayPal Pro Add-on to version 1.1.0 or later.
If exploited, CVE-2015-9373 can allow attackers to execute arbitrary JavaScript in the context of the user's browser session.
CVE-2015-9373 affects the iThemes PayPal Pro Add-on for WordPress versions earlier than 1.1.0.
A temporary workaround for CVE-2015-9373 may include disabling the affected plugin until an update can be applied.