CVE-2015-9531: XSS
The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9531?
CVE-2015-9531 is a vulnerability in the Easy Digital Downloads (EDD) Wish Lists extension for WordPress.
What is the severity of CVE-2015-9531?
The severity of CVE-2015-9531 is medium with a CVSS score of 6.1.
Which versions of Easy Digital Downloads (EDD) are affected by CVE-2015-9531?
EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 are affected by CVE-2015-9531.
What is the affected component of CVE-2015-9531?
The Easy Digital Downloads (EDD) Wish Lists extension for WordPress is the affected component of CVE-2015-9531.
How do I fix CVE-2015-9531?
To fix CVE-2015-9531, upgrade Easy Digital Downloads (EDD) to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.