CVE-2015-9535: XSS
The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9535?
CVE-2015-9535 is a vulnerability in the Easy Digital Downloads (EDD) Shoppette theme for WordPress.
What is the severity of CVE-2015-9535?
CVE-2015-9535 has a severity rating of medium with a CVSS score of 6.1.
How does CVE-2015-9535 affect Easy Digital Downloads?
CVE-2015-9535 affects Easy Digital Downloads versions 1.8.x to 2.3.x.
What is XSS?
XSS stands for Cross-Site Scripting and it is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
How can I fix CVE-2015-9535 in Easy Digital Downloads?
To fix CVE-2015-9535 in Easy Digital Downloads, you should update to the latest version of the Shoppette theme and Easy Digital Downloads.