CVE-2015-9378: XSS
iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9378?
CVE-2015-9378 is a vulnerability found in the iThemes Builder Theme Market plugin for WordPress that allows for cross-site scripting (XSS) attacks.
What is the severity of CVE-2015-9378?
The severity of CVE-2015-9378 is medium with a CVSS score of 6.1.
How does CVE-2015-9378 impact iThemes Builder Theme Market?
CVE-2015-9378 allows attackers to inject malicious scripts into the plugin, potentially compromising the security and integrity of the affected WordPress websites.
How can I fix CVE-2015-9378?
To fix CVE-2015-9378, it is recommended to update the iThemes Builder Theme Market plugin to version 5.1.27 or later, as this version includes a security patch that addresses the vulnerability.
Where can I find more information about CVE-2015-9378?
More information about CVE-2015-9378 can be found on the official iThemes blog and the Sucuri security blog.