Impact
The vulnerability is a reflected Cross Site Scripting flaw in the Link Whisper Free plugin for WordPress. An attacker can inject malicious script into a URL that is reflected back to visitors who click the link, allowing arbitrary code execution in their browsers. This could lead to credential theft, session hijack, or further page compromise, affecting confidentiality, integrity, and availability of the site for users that access the vulnerable links.
Affected Systems
The flaw affects installations of the Link Whisper Free plugin version 0.9.4 and earlier, which is distributed by Spencer Haws. Users deploying these versions of the plugin in a WordPress environment are vulnerable. No version narrowing beyond 0.9.4 is provided.
Risk and Exploitability
The CVSS score of 7.1 places this issue in the High severity range. The EPSS score is not available, so the probability of exploitation is unknown, but reflective XSS can be easily triggered via crafted links that may be circulated or embedded. The vulnerability is not listed in the CISA KEV catalog, yet the high impact warrants timely action. Exploitation requires an injected URL visible to users; any user with sufficient permissions to post link content could embed the malicious link, and unsuspecting visitors would be affected.
OpenCVE Enrichment