Impact
The vulnerability is a lack of proper escaping in certain query parameters on front‑end directory pages of the Link Library plugin. When a user visits a page that contains the link_tags or link_price parameters, an attacker can embed malicious JavaScript, which is then reflected in the generated link URLs. This allows the attacker to execute arbitrary script in the victim’s browser. Because the flaw is reflected, it can affect any visitor, including logged‑in administrators, offering a path to session hijacking or defacement.
Affected Systems
Vendors: Link Library WordPress plugin. Affected versions are all releases prior to 7.9.6. Any WordPress site that installs this plugin before the stated version is vulnerable.
Risk and Exploitability
The flaw is a classical reflected XSS. Exploitation requires that a victim visit a crafted URL or click a manipulated link, a scenario that is trivial for an attacker to deliver via a phishing message or a compromised link. No EPSS score is published, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. Nevertheless, the potential to compromise privileged administrators or deface the site makes the risk significant enough to warrant an immediate fix.
OpenCVE Enrichment