CVE-2017-15811: Pootlepress Pootle Button

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitable via wp-admin/admin-ajax.php.

Affected products

  • Pootlepress Pootle Button: version 1.0.0 only; version 1.1.0 only; version 1.1.1 only

Published 2017-10-23. Last modified 2026-06-17.