Medium severity5.4NVD Advisory· Published Oct 23, 2017· Updated Jun 17, 2026
CVE-2017-15811
CVE-2017-15811
Description
The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitable via wp-admin/admin-ajax.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:pootlepress:pootle_button:1.0.0:*:*:*:*:wordpress:*:*+ 2 more
- cpe:2.3:a:pootlepress:pootle_button:1.0.0:*:*:*:*:wordpress:*:*
- cpe:2.3:a:pootlepress:pootle_button:1.1.0:*:*:*:*:wordpress:*:*
- cpe:2.3:a:pootlepress:pootle_button:1.1.1:*:*:*:*:wordpress:*:*
Patches
Vulnerability mechanics
References
3- plugins.trac.wordpress.org/changeset/1745805/pootle-button/tags/nvdPatchThird Party Advisory
- packetstormsecurity.com/files/144582/WordPress-Pootle-Button-1.1.1-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- wpvulndb.com/vulnerabilities/8930nvdThird Party Advisory
News mentions
0No linked articles in our index yet.