CVE-2015-9509: XSS
The Easy Digital Downloads (EDD) Content Restriction extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2015-9509?
The vulnerability CVE-2015-9509 is an XSS vulnerability in the Easy Digital Downloads (EDD) Content Restriction extension for WordPress.
What is the severity of CVE-2015-9509?
The severity of CVE-2015-9509 is medium, with a CVSS score of 6.1.
Which versions of Easy Digital Downloads (EDD) are affected by CVE-2015-9509?
Easy Digital Downloads (EDD) versions 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 are affected by CVE-2015-9509.
How does the vulnerability CVE-2015-9509 affect the Easy Digital Downloads (EDD) Content Restriction extension?
The vulnerability CVE-2015-9509 allows for cross-site scripting (XSS) attacks because the add_query_arg function is misused.
Is there a fix available for CVE-2015-9509?
Yes, a security fix has been released for CVE-2015-9509. It is recommended to update to the latest version of the Easy Digital Downloads (EDD) Content Restriction extension for WordPress.