CVE-2015-9507: XSS
The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9507?
CVE-2015-9507 is classified as a cross-site scripting (XSS) vulnerability that can allow attackers to inject scripts into web pages.
How do I fix CVE-2015-9507?
To fix CVE-2015-9507, update the Easy Digital Downloads plugin to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7 or later.
Which versions of Easy Digital Downloads are affected by CVE-2015-9507?
CVE-2015-9507 affects Easy Digital Downloads versions prior to 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, and 2.3.7.
What type of vulnerability is CVE-2015-9507?
CVE-2015-9507 is a cross-site scripting (XSS) vulnerability due to the misuse of the add_query_arg function.
Is the Attach Accounts to Orders extension for Easy Digital Downloads affected by CVE-2015-9507?
Yes, the Attach Accounts to Orders extension for Easy Digital Downloads is also vulnerable to CVE-2015-9507.