Medium severity6.1NVD Advisory· Published Oct 24, 2017· Updated May 13, 2026
CVE-2017-15863
CVE-2017-15863
Description
Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php.
Affected products
1- cpe:2.3:a:wp_no_external_links_project:wp_no_external_links:*:*:*:*:*:wordpress:*:*Range: <=3.5.18
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- lists.openwall.net/full-disclosure/2017/06/02/3nvdExploitMailing ListThird Party AdvisoryVDB Entry
- wordpress.org/plugins/wp-noexternallinks/nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.