Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup inlinkz-scripter allows DOM-Based XSS.This issue affects EZ InLinkz linkup: from n/a through <= 0.18.
Published: 2025-02-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user‑controlled input in the WordPress EZ InLinkz linkup plugin (CWE‑79) enables a DOM‑based Cross‑Site Scripting attack. When a malicious input is processed by the plugin, arbitrary JavaScript can run in the context of the affected site, potentially leading to session hijacking, defacement, or credential theft. The vulnerability is limited to the client side and does not grant the attacker direct access to the server, but any user who visits a crafted page can be impacted. Based on the description, it is inferred that the flaw is client‑side only and requires user interaction to trigger exploitation.

Affected Systems

The issue affects the inlinkz: EZ InLinkz linkup plugin for WordPress versions up to and including 0.18. Users who have installed any of these versions need to check and apply a fix.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, and the EPSS score is below 1%, suggesting that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, so there is no known exploitation in the wild. However, because the flaw requires user interaction to run malicious code in a browser, administrators should treat it as a moderate risk to any users who may view compromised pages and should move quickly to mitigate. Based on the description, it is inferred that the vulnerability is client‑side only and needs a victim to visit a malicious page for exploitation.

Generated by OpenCVE AI on May 2, 2026 at 09:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the EZ InLinkz linkup plugin to the latest available version that resolves the CWE‑79 XSS flaw.
  • If an upgrade is not possible, immediately disable or uninstall the plugin to eliminate the CWE‑79 attack surface.
  • As a temporary safeguard, configure a strict Content Security Policy that blocks the execution of inline scripts and disallows unsafe‑eval on the site, mitigating the CWE‑79 XSS risk.

Generated by OpenCVE AI on May 2, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4328 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup allows DOM-Based XSS. This issue affects EZ InLinkz linkup: from n/a through 0.18.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup allows DOM-Based XSS. This issue affects EZ InLinkz linkup: from n/a through 0.18. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup inlinkz-scripter allows DOM-Based XSS.This issue affects EZ InLinkz linkup: from n/a through <= 0.18.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 24 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup allows DOM-Based XSS. This issue affects EZ InLinkz linkup: from n/a through 0.18.
Title WordPress EZ InLinkz linkup plugin <= 0.18 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:48.220Z

Reserved: 2025-02-21T16:45:48.523Z

Link: CVE-2025-27329

cve-icon Vulnrichment

Updated: 2025-02-24T16:52:10.236Z

cve-icon NVD

Status : Deferred

Published: 2025-02-24T15:15:18.493

Modified: 2026-06-17T09:03:24.660

Link: CVE-2025-27329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:15:26Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')