CVE-2015-9376: XSS
Published Aug 28, 2019
·Updated
iThemes Mobile before 1.2.8 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
1 affected component
iThemes Mobile Wordpress<1.2.8
Event History
Aug 28, 2019
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
Description
Frequently Asked Questions
1
What is CVE-2015-9376?
CVE-2015-9376 is a cross-site scripting (XSS) vulnerability in the iThemes Mobile plugin for WordPress.
2
What is the severity of CVE-2015-9376?
CVE-2015-9376 has a severity score of 6.1, which is considered medium.
3
How does CVE-2015-9376 affect iThemes Mobile?
CVE-2015-9376 affects iThemes Mobile versions up to and including 1.2.8 for WordPress.
4
How can the XSS vulnerability in iThemes Mobile be exploited?
The XSS vulnerability in iThemes Mobile can be exploited through the use of the add_query_arg() and remove_query_arg() functions.
5
Is there a fix for CVE-2015-9376?
Yes, the vulnerability can be fixed by updating iThemes Mobile to version 1.2.8 or above.