CVE-2015-9497: XSS
Published Oct 22, 2019
·Updated
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
Affected Software
1 affected component
Ad Inserter Project Ad Inserter Wordpress<1.5.3
Event History
Oct 22, 2019
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9497?
CVE-2015-9497 has a medium severity level due to its potential for CSRF leading to XSS vulnerabilities.
2
How do I fix CVE-2015-9497?
To fix CVE-2015-9497, update the Ad Inserter plugin to version 1.5.3 or later.
3
What systems are affected by CVE-2015-9497?
CVE-2015-9497 affects versions of the Ad Inserter plugin prior to 1.5.3 used on WordPress sites.
4
What type of vulnerability is CVE-2015-9497?
CVE-2015-9497 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Cross-Site Scripting (XSS).
5
Can CVE-2015-9497 be exploited remotely?
Yes, CVE-2015-9497 can be exploited remotely if an attacker can trick a logged-in user into performing unauthorized actions.