CVE-2015-9379: XSS
iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9379?
CVE-2015-9379 is a vulnerability in iThemes Builder Style Manager for WordPress that allows XSS attacks via add_query_arg() and remove_query_arg().
How severe is CVE-2015-9379?
CVE-2015-9379 has a severity rating of 6.1 (medium).
What is the affected software for CVE-2015-9379?
The affected software for CVE-2015-9379 is iThemes Builder Style Manager for WordPress versions up to and excluding 0.7.7.
How can I fix CVE-2015-9379?
To fix CVE-2015-9379, update iThemes Builder Style Manager for WordPress to version 0.7.7 or higher.
Where can I find more information about CVE-2015-9379?
You can find more information about CVE-2015-9379 in the following references: [link1](https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html), [link2](https://ithemes.com/coordinated-wordpress-plugin-security-update/)