Cross-site Scripting Vulnerability in Link Whisper Free Plugin by Spencer Haws
CVE-2026-22357
7.1HIGH
What is CVE-2026-22357?
The Link Whisper Free plugin, developed by Spencer Haws, has been discovered to have a Cross-site Scripting (XSS) vulnerability. This flaw allows attackers to inject malicious scripts into web pages generated by the plugin, potentially leading to the exposure of sensitive user information. Affected versions are those prior to and including 0.9.0. It is crucial for users to update their installations to mitigate this security risk.
Affected Version(s)
Link Whisper Free 0 <= 0.9.2