Impact
A stored Cross‑Site Scripting flaw exists in the WordPress No External Links plugin that allows an unauthenticated attacker to inject arbitrary JavaScript into a log URL accessed through the \/goto\/base64 endpoint. The injected scripts execute in the context of any user who views the compromised page, potentially enabling credential theft, session hijacking, or defacement. The vulnerability stems from insufficient input sanitization and output escaping when the administrator has enabled the ‘Link Encoding: Base64’ option.
Affected Systems
All releases of the WordPress No External Links plugin up to and including version 5.2.0 are affected. The flaw is specific to installations where the Base64 link encoding feature is turned on. Users of newer releases (5.2.1 and later) are not impacted.
Risk and Exploitability
The flaw carries a CVSS score of 7.2, indicating a high potential for damage. No EPSS data is available, but the lack of KEV listing suggests it has not yet been widely exploited in the wild. Because the attack requires no authentication and is trivial to trigger via the redirect URL, the likelihood of exploitation remains substantial for vulnerable sites that have the Base64 encoding enabled.
OpenCVE Enrichment