Digital Store [digital-store] < 1.3.3
unknown
[en] The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Oct 23, 2019
CVE-2015-9532 on NVD →
Easy Digital Downloads (EDD) Digital Store < 1.3.3 - Cross-Site Scripting
medium
The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
- CVSS:
- 6.1
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Apr 20, 2015
CVE-2015-9532 on NVD →
Digital Store [digital-store] < 1.3.3 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the theme.
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Apr 20, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database