Medium severity5.4NVD Advisory· Published Oct 23, 2017· Updated May 13, 2026
CVE-2017-15811
CVE-2017-15811
Description
The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitable via wp-admin/admin-ajax.php.
Affected products
3cpe:2.3:a:pootlepress:pootle_button:1.0.0:*:*:*:*:wordpress:*:*+ 2 more
- cpe:2.3:a:pootlepress:pootle_button:1.0.0:*:*:*:*:wordpress:*:*
- cpe:2.3:a:pootlepress:pootle_button:1.1.0:*:*:*:*:wordpress:*:*
- cpe:2.3:a:pootlepress:pootle_button:1.1.1:*:*:*:*:wordpress:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- plugins.trac.wordpress.org/changeset/1745805/pootle-button/tags/nvdPatchThird Party Advisory
- packetstormsecurity.com/files/144582/WordPress-Pootle-Button-1.1.1-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- wpvulndb.com/vulnerabilities/8930nvdThird Party Advisory
News mentions
0No linked articles in our index yet.