CVE-2015-9517: XSS
The Easy Digital Downloads (EDD) Manual Purchases extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2015-9517.
Which software is affected by this vulnerability?
The Easy Digital Downloads (EDD) Manual Purchases extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7.
What is the severity of the CVE-2019-9517 vulnerability?
The severity of the CVE-2019-9517 vulnerability is medium with a CVSS score of 6.1.
What is the CWE category of this vulnerability?
The CWE category of this vulnerability is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
How can I fix the CVE-2019-9517 vulnerability?
To fix the CVE-2019-9517 vulnerability, you should update the Easy Digital Downloads (EDD) Manual Purchases extension for WordPress to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.