---
cve: "CVE-2015-9521"
severity: "LOW"
cvss: 3.1
epss: "92%"
vendor: "n/a"
kev: false
exploited: false
published: "2019-10-23 17:15:12"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T01:20:42+02:00"
---

# CVE-2015-9521

> 3.1 LOW

## Beschreibung

The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

## Referenzen

- <https://web.archive.org/web/20160921003517/https://easydigitaldownloads.com/blog/security-fix-released/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2015-9521) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
