Impact
The Link Whisper Free plugin for WordPress is vulnerable to stored cross‑site scripting through the user_id parameter. Insufficient input sanitization and output escaping allow an unauthenticated attacker to inject arbitrary JavaScript that is saved in the database and executed whenever a user loads an affected page.
Affected Systems
The vulnerability applies to all releases of the Link Whisper Free plugin up to and including version 0.9.0. Any WordPress site that has installed a version of the plugin within this range and has not applied an update that removes the flaw is affected.
Risk and Exploitability
The CVSS score of 7.2 indicates medium‑to‑high severity. The flaw has no authentication requirement, meaning any internet user can exploit it. EPSS data is not available, but the widespread use of the plugin and the nature of stored cross‑site scripting make it a realistic threat. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment