Reflected Cross-Site Scripting Vulnerability in Link Library Plugin for WordPress
CVE-2024-13404
6.1MEDIUM
Summary
The Link Library plugin for WordPress is susceptible to a Reflected Cross-Site Scripting attack through the 'searchll' parameter due to inadequate input sanitization and output escaping methods. This vulnerability allows unauthenticated attackers to inject malicious web scripts into web pages, which can then be executed when users are lured into clicking on a manipulated link. It affects all versions up to and including 7.7.2, posing a significant risk to users and their data if proper security measures are not implemented.
Affected Version(s)
Link Library * <= 7.7.2
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Colin Xu