CVE-2019-17515: XSS
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-17515?
CVE-2019-17515 is a vulnerability in the CleanTalk cleantalk-spam-protect plugin before version 5.127.4 for WordPress, which allows an attacker to execute arbitrary HTML and JavaScript code via the 'from' or 'till' parameter.
How does CVE-2019-17515 impact WordPress?
CVE-2019-17515 impacts WordPress by enabling an attacker to execute arbitrary HTML and JavaScript code on a vulnerable website that has the CleanTalk cleantalk-spam-protect plugin installed.
What is the severity of CVE-2019-17515?
CVE-2019-17515 has a severity keyword of 'medium' and a severity value of 6.1 on the CVSSv3 scale.
Which component(s) of the CleanTalk cleantalk-spam-protect plugin are affected by CVE-2019-17515?
The component(s) affected by CVE-2019-17515 are 'inc/cleantalk-users.php' and 'inc/cleantalk-comments.php' of the CleanTalk cleantalk-spam-protect plugin.
How can the vulnerability CVE-2019-17515 be fixed?
To fix the vulnerability CVE-2019-17515, users should update the CleanTalk cleantalk-spam-protect plugin to version 5.127.4 or later.