Stored Cross-Site Scripting in myLinksDump Plugin for WordPress
CVE-2026-2288
4.8MEDIUM
What is CVE-2026-2288?
The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping in the 'link_title' parameter. This vulnerability affects multi-site installations and those where unfiltered_html has been disabled, allowing authenticated attackers with administrator-level access to inject arbitrary web scripts. These scripts execute whenever a user accesses the compromised page, posing significant security risks.
Affected Version(s)
myLinksDump 0 <= 1.6