Reflected Cross-Site Scripting Vulnerability in Link Library WordPress Plugin
CVE-2026-78393
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 25 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-78393?
The Link Library WordPress plugin prior to version 7.9.6 is vulnerable due to inadequate escaping of certain parameters when generating links for its front-end directory pages. This oversight allows for the exploitation of Reflected Cross-Site Scripting attacks, affecting any visitor to the site, including logged-in administrators. Attackers can craft malicious requests, resulting in JavaScript execution in users' browsers, potentially compromising sensitive information and cookies.
Affected Version(s)
Link Library 0 < 7.9.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.