CVE-2017-15863: Wp No External Links Project Wp No External Links

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php.

Affected products

Published 2017-10-24. Last modified 2026-06-17.