Easy Digital Downloads – Upload File [edd-upload-file] < 1.0.4
unknown
[en] The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Oct 23, 2019
CVE-2015-9530 on NVD →
Easy Digital Downloads – Upload File <= 1.0.4 - Arbitrary File Upload/Deletion
critical
The Easy Digital Downloads – Upload File for WordPress is vulnerable to Arbitrary File Upload/Delete and Remote Code Execution via the 'edd_upload_file_delete', 'edd_upload_file_view_files', and 'create_upload_dir' functions in versions up to, and including, 1.0.4. This makes it possible for authenticated attackers to...
- CVSS:
- 9.8
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Apr 9, 2015
CVE-2015-9530 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database