WordPress Plugin Vulnerabilities

Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb Links

Description

The plugin does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could be used against any visitor, including logged-in administrators.

Proof of Concept

Affects Plugins

Fixed in 7.9.6

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-09-23 (about 2 days ago)
Added
2026-09-23 (about 1 day ago)
Last Updated
2026-09-23 (about 1 day ago)

Other