CVE-2015-9373: XSS
Published Aug 28, 2019
·Updated
PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
1 affected component
WebDevStudios Ithemes Paypal Pro Wordpress<1.1.0
Event History
Aug 28, 2019
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9373?
CVE-2015-9373 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting (XSS).
2
How do I fix CVE-2015-9373?
To remediate CVE-2015-9373, update the iThemes PayPal Pro Add-on to version 1.1.0 or later.
3
What are the consequences of CVE-2015-9373 if exploited?
If exploited, CVE-2015-9373 can allow attackers to execute arbitrary JavaScript in the context of the user's browser session.
4
Which software versions are affected by CVE-2015-9373?
CVE-2015-9373 affects the iThemes PayPal Pro Add-on for WordPress versions earlier than 1.1.0.
5
Is there a workaround for CVE-2015-9373 if I cannot update immediately?
A temporary workaround for CVE-2015-9373 may include disabling the affected plugin until an update can be applied.