CVE-2015-9519: XSS
The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2015-9519.
What is the severity level of CVE-2015-9519?
The severity level of CVE-2015-9519 is medium.
Which software is affected by CVE-2015-9519?
The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 is affected.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The CWE ID for CVE-2015-9519 is CWE-79.
How can I fix the CVE-2015-9519 vulnerability?
To fix the CVE-2015-9519 vulnerability, you should update Easy Digital Downloads (EDD) PDF Stamper extension for WordPress to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.