CVE-2015-9521: XSS
The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9521?
CVE-2015-9521 has a moderate severity level due to the potential for XSS attacks.
How do I fix CVE-2015-9521?
To fix CVE-2015-9521, update the Easy Digital Downloads Pushover Notifications extension to a version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7 or later.
Which versions of Easy Digital Downloads are affected by CVE-2015-9521?
CVE-2015-9521 affects Easy Digital Downloads versions prior to 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, and 2.3.7.
What type of vulnerability is CVE-2015-9521?
CVE-2015-9521 is an XSS (Cross-Site Scripting) vulnerability.
What systems are impacted by CVE-2015-9521?
CVE-2015-9521 impacts WordPress installations using the affected versions of the Easy Digital Downloads Pushover Notifications extension.