Vulnerabilities > Sandhillsdev > Easy Digital Downloads > 2.3.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-10-23 | CVE-2015-9526 | Cross-site Scripting vulnerability in multiple products The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | 4.3 |
2019-10-23 | CVE-2015-9525 | Cross-site Scripting vulnerability in multiple products The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | 4.3 |
2019-08-16 | CVE-2019-15116 | Cross-site Scripting vulnerability in Sandhillsdev Easy Digital Downloads The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging. | 4.3 |