Cross-Site Scripting Vulnerability in Pootle Button Plugin for WordPress
CVE-2017-15811
5.4MEDIUM
What is CVE-2017-15811?
The Pootle Button plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability prior to version 1.2.0. This flaw occurs due to improper handling of user input in the 'assets_url' parameter found within the 'assets/dialog.php' file. An attacker can exploit this weakness through the 'wp-admin/admin-ajax.php' endpoint, potentially allowing malicious scripts to be executed in the context of users visiting the affected site.