First published: Wed Oct 23 2019(Updated: )
The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Digital Downloads | >=1.8<1.8.7 | |
Easy Digital Downloads | >=1.9<1.9.10 | |
Easy Digital Downloads | >=2.0<2.0.5 | |
Easy Digital Downloads | >=2.1<2.1.11 | |
Easy Digital Downloads | >=2.2<2.2.9 | |
Easy Digital Downloads | >=2.3<2.3.7 | |
Easydigitaldownloads Software Licensing |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9528 is considered a medium severity vulnerability due to the potential for XSS attacks.
To fix CVE-2015-9528, update the Easy Digital Downloads Software Licensing extension to versions 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7 or later.
CVE-2015-9528 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Affected versions of Easy Digital Downloads include 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7.
If you cannot update, consider disabling the affected plugin and reviewing your website for any signs of compromise.