First published: Wed Oct 23 2019(Updated: )
The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Digital Downloads | >=1.8<1.8.7 | |
Easy Digital Downloads | >=1.9<1.9.10 | |
Easy Digital Downloads | >=2.0<2.0.5 | |
Easy Digital Downloads | >=2.1<2.1.11 | |
Easy Digital Downloads | >=2.2<2.2.9 | |
Easy Digital Downloads | >=2.3<2.3.7 | |
Easydigitaldownloads Pdf Stamper |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2015-9519.
The severity level of CVE-2015-9519 is medium.
The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 is affected.
The CWE ID for CVE-2015-9519 is CWE-79.
To fix the CVE-2015-9519 vulnerability, you should update Easy Digital Downloads (EDD) PDF Stamper extension for WordPress to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.