Cross-Site Scripting Vulnerability in Link Whisper Free by Spencer Haws
CVE-2025-67927
6.1MEDIUM
What is CVE-2025-67927?
The Link Whisper Free plugin, developed by Spencer Haws, has a vulnerability that allows for improper neutralization of user inputs during web page generation. This can lead to a reflected Cross-Site Scripting (XSS) attack, where an attacker can inject malicious scripts into the web pages viewed by users. The vulnerability affects all versions of Link Whisper Free up to and including 0.8.8, thereby posing a risk to data integrity and potentially compromising user security.
Affected Version(s)
Link Whisper Free 0 <= 0.8.8