CVE-2015-9529: XSS
The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2015-9529.
What is the severity of CVE-2015-9529?
The severity of CVE-2015-9529 is medium.
Which software is affected by CVE-2015-9529?
The Easy Digital Downloads Stripe extension for WordPress versions 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 are affected by CVE-2015-9529.
What is the description of CVE-2015-9529?
CVE-2015-9529 is a vulnerability in the Easy Digital Downloads Stripe extension for WordPress, which allows for cross-site scripting (XSS) attacks due to misuse of the add_query_arg function.
How can I fix the vulnerability CVE-2015-9529?
To fix the vulnerability, update the Easy Digital Downloads Stripe extension to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.