Security readout for executives and security teams
Plain-English summary
This is a cross-site scripting issue in the Easy Digital Downloads Lattice WordPress theme when used with several older EDD release branches. Affected sites could expose visitors or administrators to malicious script execution in the browser. The source bundle does not provide a CVSS score or active exploitation evidence.
Executive priority
Handle as a legacy ecommerce exposure. It is not KEV-listed in the bundle, but affected WordPress stores should be upgraded or retired to reduce browser-based compromise risk.
Technical view
CVE-2015-9533 describes XSS caused by misuse of WordPress add_query_arg in the EDD Lattice theme, affecting EDD 1.8.x through 2.3.x before specified fixed releases. The bundle does not identify CWE, attack vector, authentication requirements, or exploit maturity beyond the XSS description.
Likely exposure
Exposure is likely limited to WordPress sites using the EDD Lattice theme with affected EDD versions before 1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, or 2.3.7.
Exploitation context
The provided sources do not show CISA KEV listing or active exploitation. Treat this as a known historical XSS issue requiring verification on legacy WordPress ecommerce installations.
Researcher notes
Evidence is sparse: the bundle identifies XSS and affected EDD version ranges but lacks CVSS, CWE, exploit prerequisites, and fixed code details. Avoid assuming broader plugin exposure beyond the named Lattice theme context.
Mitigation direction
- Upgrade EDD to the fixed version for the installed release branch.
- Check Easy Digital Downloads vendor guidance for current supported remediation.
- Retire or replace unsupported Lattice theme deployments.
- Prioritize admin-facing or internet-facing ecommerce sites first.
Validation and detection
- Inventory WordPress sites for the EDD Lattice theme.
- Confirm installed EDD version against the affected version ranges.
- Review vendor changelog or advisory for the applied security fix.
- Check whether vulnerable theme files remain active after upgrades.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2015-9533 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://web.archive.org/web/20160921003517/https://easydigitaldownloads.com/blog/security-fix-released/CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
