CVE-2015-9514: XSS
The Easy Digital Downloads (EDD) Free Downloads extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9514?
CVE-2015-9514 is a vulnerability in the Easy Digital Downloads (EDD) Free Downloads extension for WordPress.
How does CVE-2015-9514 affect the software?
CVE-2015-9514 affects EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7.
What is the severity of CVE-2015-9514?
CVE-2015-9514 has a severity rating of 6.1 (Medium).
What is the CWE ID for CVE-2015-9514?
The CWE ID for CVE-2015-9514 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
How do I fix CVE-2015-9514?
To fix CVE-2015-9514, upgrade to EDD versions 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.