CVE-2017-15811
23.10.2017, 17:29
The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitable via wp-admin/admin-ajax.php.
Vendor | Product | Version |
---|---|---|
pootlepress | pootle_button | 1.0.0 |
pootlepress | pootle_button | 1.1.0 |
pootlepress | pootle_button | 1.1.1 |
𝑥
= Vulnerable software versions