CVE-2015-9508: XSS
Published Oct 23, 2019
·Updated
The Easy Digital Downloads (EDD) Commissions extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
14 affected components
All of the following
Any of the following
Awesomemotive Easy Digital Downloads Wordpress>=1.8<1.8.7
Awesomemotive Easy Digital Downloads Wordpress>=1.9<1.9.10
Awesomemotive Easy Digital Downloads Wordpress>=2.0<2.0.5
Awesomemotive Easy Digital Downloads Wordpress>=2.1<2.1.11
Awesomemotive Easy Digital Downloads Wordpress>=2.2<2.2.9
Awesomemotive Easy Digital Downloads Wordpress>=2.3<2.3.7
Easydigitaldownloads Commissions Easy Digital Downloads
Sandhillsdev Easy Digital Downloads Wordpress>=1.8<1.8.7
Sandhillsdev Easy Digital Downloads Wordpress>=1.9<1.9.10
Sandhillsdev Easy Digital Downloads Wordpress>=2.0<2.0.5
Sandhillsdev Easy Digital Downloads Wordpress>=2.1<2.1.11
Sandhillsdev Easy Digital Downloads Wordpress>=2.2<2.2.9
Sandhillsdev Easy Digital Downloads Wordpress>=2.3<2.3.7
Easydigitaldownloads Commissions Easy Digital Downloads
Event History
Oct 23, 2019
CVE Published
via MITRE·04:12 PM
Data Sourced
via MITRE·04:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2015-9508.
2
What is the severity of CVE-2015-9508?
The severity of CVE-2015-9508 is medium with a severity value of 6.1.
3
What is the affected software for CVE-2015-9508?
The affected software for CVE-2015-9508 is Easy Digital Downloads (EDD) Commissions extension for WordPress.
4
How can this vulnerability be exploited?
This vulnerability can be exploited through XSS (Cross-Site Scripting) attacks.
5
Is there a fix for CVE-2015-9508?
Yes, a security fix has been released. Please refer to the reference link for more information.