Impact
The vulnerability allows an unauthenticated attacker to inject arbitrary JavaScript via the *url* parameter on the plugin’s redirect page. Because the input is neither sanitized nor escaped, the malicious script is reflected back to the victim’s browser. If a user clicks a crafted link, the payload executes in the victim’s context, enabling session hijacking, cookie theft, or phishing attacks. This flaw maps to CWE‑79, a classic reflected cross‑site scripting weakness.
Affected Systems
All instances of the MinhNhut Link Gateway WordPress plugin with versions up to and including 3.6.1 are affected. No other products or versions are known to contain this flaw.
Risk and Exploitability
The CVSS score of 6.1 places the issue in the medium severity range. EPSS data is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. Attackers would most likely use a socially engineered link that leads a victim’s browser to the vulnerable redirect page. Because the flaw is input‑based and does not require privileged access, the risk is moderate but still warrants prompt remediation.
OpenCVE Enrichment