CVE-2015-9525: XSS
The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9525?
CVE-2015-9525 is a vulnerability in the Easy Digital Downloads (EDD) Recurring Payments extension for WordPress.
How does CVE-2015-9525 affect Easy Digital Downloads?
CVE-2015-9525 affects Easy Digital Downloads versions 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7.
What is the severity of CVE-2015-9525?
CVE-2015-9525 has a severity score of 6.1 (Medium).
What is the Common Weakness Enumeration (CWE) ID for CVE-2015-9525?
The CWE ID for CVE-2015-9525 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
How can I fix CVE-2015-9525?
To fix CVE-2015-9525, you should upgrade Easy Digital Downloads to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.