The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action.
Metrics
Affected Vendors & Products
References
History
Sat, 08 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Sat, 08 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action. | |
| Title | Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-08T06:00:11.068Z
Reserved: 2026-07-22T09:21:40.853Z
Link: CVE-2026-16535
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-08T08:00:11Z