CVE-2015-9534: XSS
The Easy Digital Downloads (EDD) Quota theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9534?
CVE-2015-9534 is a vulnerability in the Easy Digital Downloads (EDD) Quota theme for WordPress.
How does CVE-2015-9534 affect the Easy Digital Downloads (EDD) Quota theme for WordPress?
CVE-2015-9534 allows for cross-site scripting (XSS) attacks due to misuse of the add_query_arg function.
What is the severity of CVE-2015-9534?
CVE-2015-9534 has a severity level of 6.1 (Medium).
Which versions of Easy Digital Downloads (EDD) Quota theme for WordPress are affected by CVE-2015-9534?
Versions 1.8.x through 2.3.x of Easy Digital Downloads (EDD) Quota theme for WordPress are affected by CVE-2015-9534.
How can I fix CVE-2015-9534 in Easy Digital Downloads (EDD) Quota theme for WordPress?
To fix CVE-2015-9534, update Easy Digital Downloads (EDD) Quota theme for WordPress to version 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7 or later.