CVE-2015-9524: XSS
The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9524?
CVE-2015-9524 is a vulnerability in the Easy Digital Downloads (EDD) Recount Earnings extension for WordPress.
What is the severity of CVE-2015-9524?
CVE-2015-9524 has a severity rating of 6.1, which is considered medium.
How does CVE-2015-9524 affect Easy Digital Downloads?
CVE-2015-9524 affects Easy Digital Downloads versions 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7.
What is XSS?
XSS stands for Cross-Site Scripting, which is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
How can I fix CVE-2015-9524?
To fix CVE-2015-9524, you should update Easy Digital Downloads to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.