CVE-2015-9505: XSS
The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9505?
CVE-2015-9505 is a vulnerability in the Easy Digital Downloads (EDD) core component for WordPress that allows for cross-site scripting (XSS) attacks.
How severe is CVE-2015-9505?
CVE-2015-9505 has a severity rating of 6.1 which is considered medium.
Which versions of Easy Digital Downloads (EDD) are affected by CVE-2015-9505?
Easy Digital Downloads (EDD) versions 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress are affected by CVE-2015-9505.
What is the impact of CVE-2015-9505?
CVE-2015-9505 allows attackers to execute malicious scripts in the context of a user's browser, potentially leading to unauthorized actions or access to sensitive information.
How can I fix CVE-2015-9505?
To fix CVE-2015-9505, it is recommended to update Easy Digital Downloads (EDD) to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7, which have the necessary security patches.