CVE-2015-9516: XSS
The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9516?
CVE-2015-9516 is a vulnerability in the Easy Digital Downloads (EDD) Invoices extension for WordPress.
How does CVE-2015-9516 affect Easy Digital Downloads (EDD) Invoices?
CVE-2015-9516 allows for cross-site scripting (XSS) attacks due to misuse of the add_query_arg function.
What versions of Easy Digital Downloads (EDD) are affected by CVE-2015-9516?
Versions 1.8.x, 1.9.x, 2.0.x, 2.1.x, 2.2.x, and 2.3.x of Easy Digital Downloads (EDD) before the specified patches are affected.
What is the severity of CVE-2015-9516?
CVE-2015-9516 has a severity rating of 6.1, which is considered medium.
How can I fix CVE-2015-9516?
To fix CVE-2015-9516, update Easy Digital Downloads (EDD) Invoices extension for WordPress to versions 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7, depending on your current version.