First published: Wed Oct 23 2019(Updated: )
The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Digital Downloads | >=1.8<1.8.7 | |
Easy Digital Downloads | >=1.9<1.9.10 | |
Easy Digital Downloads | >=2.0<2.0.5 | |
Easy Digital Downloads | >=2.1<2.1.11 | |
Easy Digital Downloads | >=2.2<2.2.9 | |
Easy Digital Downloads | >=2.3<2.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9505 is a vulnerability in the Easy Digital Downloads (EDD) core component for WordPress that allows for cross-site scripting (XSS) attacks.
CVE-2015-9505 has a severity rating of 6.1 which is considered medium.
Easy Digital Downloads (EDD) versions 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress are affected by CVE-2015-9505.
CVE-2015-9505 allows attackers to execute malicious scripts in the context of a user's browser, potentially leading to unauthorized actions or access to sensitive information.
To fix CVE-2015-9505, it is recommended to update Easy Digital Downloads (EDD) to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7, which have the necessary security patches.