CVE-2015-9526: XSS
The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9526?
CVE-2015-9526 has a medium severity level due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2015-9526?
To fix CVE-2015-9526, you should update the Easy Digital Downloads Reviews extension to versions 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7 or later.
What versions of Easy Digital Downloads are affected by CVE-2015-9526?
CVE-2015-9526 affects Easy Digital Downloads versions prior to 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, and 2.3.7.
Is CVE-2015-9526 a remote exploit?
CVE-2015-9526 can potentially be exploited remotely due to XSS vulnerabilities.
Who should be concerned about CVE-2015-9526?
Users of the Easy Digital Downloads Reviews extension on affected versions should take immediate action to patch or update their software.