Cross Site Scripting in wp-noexternallinks Plugin for WordPress
CVE-2017-15863
6.1MEDIUM
What is CVE-2017-15863?
A Cross Site Scripting (XSS) vulnerability is present in the wp-noexternallinks plugin for WordPress versions prior to 3.5.19. This weakness allows attackers to exploit the plugin through a crafted request containing malicious parameters in the date1 or date2 fields, specifically targeting the wp-admin/options-general.php page. Successful exploitation could lead to unauthorized actions performed on behalf of legitimate users, thereby compromising the security and integrity of the site.