Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View link-view allows Stored XSS.This issue affects Link View: from n/a through <= 0.8.0.
Published: 2025-08-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored cross‑site scripting vulnerability exists in the mibuthu Link View plugin up to version 0.8.0. The plugin fails to neutralize user‑supplied input that is later rendered in the web page, allowing an attacker to inject arbitrary JavaScript that executes in the browsers of any user visiting the affected pages. This can lead to session hijacking, credential theft, defacement or the execution of malware on the client side. The weakness is a classic input‑validation flaw, identified as CWE‑79.

Affected Systems

All WordPress installations that have the mibuthu Link View plugin installed at or below version 0.8.0 are affected. The vulnerability is described as working for all releases from the initial version through 0.8.0, meaning any site that has not yet applied the latest plugin update is potentially vulnerable. No specific operating systems or runtime environments are listed as restrictions, so the flaw is likely present on any typical WordPress host that supports the plugin.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, but the EPSS score of less than 1 % shows a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog, which further points to a lower risk stance. The likely attack path involves an attacker creating or editing a link entry via the plugin’s administrative interface or a form that stores the data for later display. Once the malicious payload is stored, any site visitor who views the page containing the infected link will have the script executed. The indirect exploitation requires administrative access to the plugin or the ability to submit content that is stored and displayed, but the impact on all users who see the page can be significant if the payload succeeds.

Generated by OpenCVE AI on April 30, 2026 at 08:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Link View plugin to the latest version (greater than 0.8.0) as soon as a patch is available
  • If an upgrade is not possible, disable the plugin or restrict its use to trusted administrators only to prevent malicious input from being stored
  • Implement a site‑wide XSS protection strategy such as a Web Application Firewall (WAF) or output‑encoding rules to mitigate the risk of any remaining injected scripts

Generated by OpenCVE AI on April 30, 2026 at 08:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26055 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View allows Stored XSS. This issue affects Link View: from n/a through 0.8.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View allows Stored XSS. This issue affects Link View: from n/a through 0.8.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View link-view allows Stored XSS.This issue affects Link View: from n/a through <= 0.8.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 28 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View allows Stored XSS. This issue affects Link View: from n/a through 0.8.0.
Title WordPress Link View plugin <= 0.8.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:51.696Z

Reserved: 2025-05-15T17:54:48.128Z

Link: CVE-2025-48110

cve-icon Vulnrichment

Updated: 2025-08-28T13:34:40.666Z

cve-icon NVD

Status : Deferred

Published: 2025-08-28T13:15:37.280

Modified: 2026-04-23T15:30:48.893

Link: CVE-2025-48110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T08:15:32Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')