Impact
The vulnerability is an improper neutralization of input during web page generation that permits arbitrary script execution in the victim's browser. An attacker could inject malicious JavaScript into input fields that the Link Library plugin renders without proper escaping, potentially leading to session hijacking, credential theft, or defacement of the site. The weakness is classified under CWE‑79, a cross‑site scripting flaw.
Affected Systems
The affected systems are sites that use the WordPress plugin Link Library with a version earlier than 7.9.4. Users who have not applied that version are exposed.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity level. The EPSS score of less than 1 % suggests that, at present, the probability of exploitation in the wild is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through user‑visible input that the plugin does not escape, but the key prerequisites are that the plugin is active and accepting input from users.
OpenCVE Enrichment