CVE-2019-15116: XSS
Published Aug 16, 2019
·Updated
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
Affected Software
2 affected components
Sandhillsdev Easy Digital Downloads Wordpress<2.9.16
Awesomemotive Easy Digital Downloads Wordpress<2.9.16
Event History
Aug 16, 2019
CVE Published
via MITRE·08:12 PM
Data Sourced
via MITRE·08:12 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15116?
CVE-2019-15116 has a medium severity rating due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2019-15116?
To fix CVE-2019-15116, update the Easy Digital Downloads plugin to version 2.9.16 or later.
3
Who is affected by CVE-2019-15116?
Users of the Easy Digital Downloads plugin for WordPress versions prior to 2.9.16 are affected by CVE-2019-15116.
4
What type of vulnerability is CVE-2019-15116?
CVE-2019-15116 is a Cross-Site Scripting (XSS) vulnerability related to IP address logging.
5
What can an attacker do with CVE-2019-15116?
An attacker can exploit CVE-2019-15116 to execute arbitrary JavaScript code in the context of a logged-in user.