Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a through <= 0.9.2.
Published: 2026-02-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Link Whisper Free plugin performs insufficient input sanitization when generating HTML, allowing malicious script payloads to be reflected back to the browser. An attacker can embed such payloads in user‑controlled fields, such as link URLs or titles, that are read and displayed by the plugin. When a visitor loads the page containing the reflected content, the injected script runs in their browser and can steal credentials, hijack sessions, deface content, or carry out other client‑side attacks without needing elevated server privileges.

Affected Systems

The vulnerability is present in all releases of the Link Whisper Free plugin provided by Spencer Haws up to version 0.9.2. No other product versions are known to be affected at the time of this analysis.

Risk and Exploitability

The base CVSS score of 7.1 indicates moderate to high severity and client‑side impact. An EPSS score of less than 1% shows that publicly documented exploitation attempts are exceedingly rare. The weakness is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is external: an attacker must supply crafted input, typically via URLs or form submissions, that is subsequently reflected in the page. No public exploit code is known, but the reflected nature of the XSS makes it simple for an attacker who can persuade a victim to click a malicious link.

Generated by OpenCVE AI on April 16, 2026 at 16:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Link Whisper Free plugin to a newer release that includes the XSS fix; if the latest version is unavailable, defer the plugin’s use until a patched version is released.
  • If updating is not immediately possible, remove or deactivate the Link Whisper Free plugin to eliminate the vulnerable component from the site.
  • Perform a comprehensive scan of site content and logs for injected script payloads, and remove or sanitize any malicious code found to prevent further exploitation.

Generated by OpenCVE AI on April 16, 2026 at 16:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a through <= 0.9.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a through <= 0.9.2.
Title WordPress Link Whisper Free plugin <= 0.9.0 - Reflected Cross Site Scripting (XSS) vulnerability WordPress Link Whisper Free plugin <= 0.9.2 - Cross Site Scripting (XSS) vulnerability

Mon, 23 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Spencer Haws
Spencer Haws link Whisper Free
Wordpress
Wordpress wordpress
Vendors & Products Spencer Haws
Spencer Haws link Whisper Free
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a through <= 0.9.0.
Title WordPress Link Whisper Free plugin <= 0.9.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Spencer Haws Link Whisper Free
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:48:46.225Z

Reserved: 2026-01-07T12:21:24.564Z

Link: CVE-2026-22357

cve-icon Vulnrichment

Updated: 2026-02-23T17:27:17.874Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T16:22:34.833

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-22357

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T16:45:25Z

Weaknesses