CVE-2015-9532: XSS
The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2015-9532.
What is the severity level of CVE-2015-9532?
The severity level of CVE-2015-9532 is medium.
How does the Easy Digital Downloads (EDD) Digital Store theme for WordPress version 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 misuse add_query_arg?
The Easy Digital Downloads (EDD) Digital Store theme for WordPress versions 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 misuse add_query_arg, resulting in a cross-site scripting (XSS) vulnerability.
What software versions are affected by CVE-2015-9532?
The software versions affected by CVE-2015-9532 are Easy Digital Downloads (EDD) Digital Store theme for WordPress versions 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7.
How can I fix the XSS vulnerability in Easy Digital Downloads (EDD) Digital Store theme for WordPress?
To fix the XSS vulnerability in Easy Digital Downloads (EDD) Digital Store theme for WordPress, update to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.