CVE-2015-9533: XSS
The Easy Digital Downloads (EDD) Lattice theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9533?
CVE-2015-9533 is a vulnerability in the Easy Digital Downloads (EDD) Lattice theme for WordPress.
What is the severity of CVE-2015-9533?
The severity of CVE-2015-9533 is medium.
How does CVE-2015-9533 affect the Easy Digital Downloads (EDD) Lattice theme?
CVE-2015-9533 allows for cross-site scripting (XSS) attacks due to the misuse of the add_query_arg function.
Which versions of Easy Digital Downloads (EDD) Lattice are affected?
Easy Digital Downloads (EDD) Lattice versions 1.8.x to 1.8.7, 1.9.x to 1.9.10, 2.0.x to 2.0.5, 2.1.x to 2.1.11, 2.2.x to 2.2.9, and 2.3.x to 2.3.7 are affected.
How can I fix CVE-2015-9533?
To fix CVE-2015-9533, update to Easy Digital Downloads (EDD) Lattice version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.