CVE-2015-9523: XSS
The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9523?
CVE-2015-9523 is a vulnerability in the Easy Digital Downloads (EDD) Recommended Products extension for WordPress.
What is the severity of CVE-2015-9523?
The severity of CVE-2015-9523 is medium with a CVSS score of 6.1.
How does CVE-2015-9523 affect Easy Digital Downloads?
CVE-2015-9523 affects Easy Digital Downloads versions 1.8.x to 2.3.x.
How can the XSS vulnerability in CVE-2015-9523 be exploited?
The XSS vulnerability in CVE-2015-9523 can be exploited through misuse of the add_query_arg function in the EDD Recommended Products extension.
Is there a fix for CVE-2015-9523?
Yes, a security fix has been released for CVE-2015-9523. It is recommended to update Easy Digital Downloads to the latest version.