CVE-2015-9377: XSS
Published Aug 28, 2019
·Updated
iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
1 affected component
iThemes Builder Theme Depot Wordpress<5.0.30
Event History
Aug 28, 2019
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9377?
The severity of CVE-2015-9377 is medium.
2
How does CVE-2015-9377 affect iThemes Builder Theme Depot?
CVE-2015-9377 affects iThemes Builder Theme Depot versions up to 5.0.30.
3
What is the CWE number for CVE-2015-9377?
The CWE number for CVE-2015-9377 is 79.
4
How can I fix CVE-2015-9377?
To fix CVE-2015-9377, update iThemes Builder Theme Depot to version 5.0.30 or higher.
5
Where can I find more information about CVE-2015-9377?
You can find more information about CVE-2015-9377 in the following references: 1. https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html 2. https://ithemes.com/coordinated-wordpress-plugin-security-update/