Impact
The flaw allows an attacker to inject arbitrary scripts by supplying a crafted value for the "type" parameter; the input is not sanitized or escaped before being placed into page output. Because the script runs in the victim’s browser when a user clicks a link containing the malicious parameter, the attacker can steal cookies, hijack sessions, or deface the page. The vulnerability is limited to unauthenticated users but requires user interaction to trigger the code execution.
Affected Systems
Any WordPress site that uses the Link Whisper Free plugin version 0.8.8 or earlier, regardless of other configuration settings.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate level of severity, while the EPSS score of less than 1 percent suggests a low probability of exploitation at present. The attack vector is network‑based, reachable through a crafted URL that must be clicked by a victim, and the flaw is not listed in CISA’s KEV catalog, so no widespread incidents have been reported to date. However, the client‑side nature of the injection means that any user who visits the malicious link could be compromised, impacting confidentiality and integrity of that user’s session.
OpenCVE Enrichment