CVE-2015-9536: XSS
The Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because addqueryarg is misused.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9536?
CVE-2015-9536 is a cross-site scripting (XSS) vulnerability in the Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress.
What is the severity of CVE-2015-9536?
CVE-2015-9536 has a severity rating of 6.1 (medium).
Which versions of Easy Digital Downloads (EDD) are affected by CVE-2015-9536?
CVE-2015-9536 affects Easy Digital Downloads (EDD) versions 1.8.x to 2.3.x.
How does CVE-2015-9536 affect the Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress?
CVE-2015-9536 allows an attacker to perform cross-site scripting (XSS) attacks due to misuse of the add_query_arg function.
Is there a fix for CVE-2015-9536?
Yes, a security fix for CVE-2015-9536 has been released. It is recommended to update to the latest version of Easy Digital Downloads (EDD) to mitigate this vulnerability.