CVE-2019-17207: XSS
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScript into an admin-only WordPress page via the wp-admin/tools.php?page=view-broken-links sfilter parameter in a search action.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-17207.
What is the severity of CVE-2019-17207?
CVE-2019-17207 has a severity rating of 5.4, which is considered medium.
What software is affected by CVE-2019-17207?
The Broken Link Checker plugin 1.11.8 for WordPress is affected by CVE-2019-17207.
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-17207?
The CWE ID for CVE-2019-17207 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
How can unauthorized users exploit CVE-2019-17207?
Unauthorized users can inject client-side JavaScript into an admin-only WordPress page via the wp-admin/tools.php?page=view-broken-... URL.