First published: Thu Sep 26 2019(Updated: )
The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=addthis_social_widget pubid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AddThis | <5.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9439 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks via CSRF.
To mitigate CVE-2015-9439, update the AddThis plugin to version 5.0.13 or later.
CVE-2015-9439 can be exploited for cross-site scripting (XSS) attacks through malicious manipulation of the pubid parameter.
Versions of the AddThis plugin before 5.0.13 are affected by CVE-2015-9439.
Yes, CVE-2015-9439 specifically affects the AddThis plugin for WordPress.