First published: Fri Aug 16 2019(Updated: )
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Digital Downloads | <2.9.16 | |
Easy Digital Downloads | <2.9.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15116 has a medium severity rating due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2019-15116, update the Easy Digital Downloads plugin to version 2.9.16 or later.
Users of the Easy Digital Downloads plugin for WordPress versions prior to 2.9.16 are affected by CVE-2019-15116.
CVE-2019-15116 is a Cross-Site Scripting (XSS) vulnerability related to IP address logging.
An attacker can exploit CVE-2019-15116 to execute arbitrary JavaScript code in the context of a logged-in user.