CVE-2015-9527: XSS
The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9527?
CVE-2015-9527 is a vulnerability in the Easy Digital Downloads (EDD) Simple Shipping extension for WordPress.
What is the severity of CVE-2015-9527?
The severity of CVE-2015-9527 is medium, with a CVSS score of 6.1.
How does CVE-2015-9527 impact Easy Digital Downloads?
CVE-2015-9527 allows for cross-site scripting (XSS) attacks in the affected versions of Easy Digital Downloads.
What versions of Easy Digital Downloads are affected by CVE-2015-9527?
Easy Digital Downloads versions 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 are affected by CVE-2015-9527.
How can I fix the CVE-2015-9527 vulnerability?
To fix the CVE-2015-9527 vulnerability, you should update Easy Digital Downloads to version 2.3.7 or later.