CVE-2015-9528: XSS
The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9528?
CVE-2015-9528 is considered a medium severity vulnerability due to the potential for XSS attacks.
How do I fix CVE-2015-9528?
To fix CVE-2015-9528, update the Easy Digital Downloads Software Licensing extension to versions 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7 or later.
What types of attacks can CVE-2015-9528 facilitate?
CVE-2015-9528 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Which versions of Easy Digital Downloads are affected by CVE-2015-9528?
Affected versions of Easy Digital Downloads include 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7.
What should I do if I cannot update to fix CVE-2015-9528?
If you cannot update, consider disabling the affected plugin and reviewing your website for any signs of compromise.