Medium severity6.1NVD Advisory· Published Nov 13, 2019· Updated Jun 17, 2026
CVE-2019-17515
CVE-2019-17515
Description
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:cleantalk:spam_protection\,_antispam\,_firewall:*:*:*:*:*:wordpress:*:*Range: <5.127.4
- CleanTalk/cleantalk-spam-protect plugindescription
- Range: <5.127.4
Patches
Vulnerability mechanics
References
3- plugins.trac.wordpress.org/changeset/2172333nvdPatchThird Party Advisory
- wordpress.org/plugins/cleantalk-spam-protect/nvdProductThird Party Advisory
- wpvulndb.com/vulnerabilities/9949nvdThird Party Advisory
News mentions
0No linked articles in our index yet.