CVE-2017-15863: Wp No External Links Project Wp No External Links
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php.
Affected products
- Wp No External Links Project Wp No External Links: up to and including 3.5.18
Published 2017-10-24. Last modified 2026-06-17.