CVE-2017-15811: Pootlepress Pootle Button
Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.
The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitable via wp-admin/admin-ajax.php.
Affected products
- Pootlepress Pootle Button: version 1.0.0 only; version 1.1.0 only; version 1.1.1 only
Published 2017-10-23. Last modified 2026-06-17.