GHSA-gqp5-7wwf-v82xMediumCVSS 6.1

The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before...

Published
August 8, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (1)

📋 Description

The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action.

🔗 References (3)