CyberRota Analysis
AI-GeneratedThe Link Library WordPress plugin prior to version 7.9.4 is vulnerable to Reflected Cross-Site Scripting (XSS) due to inadequate sanitization and escaping of user input. This flaw allows unauthenticated attackers to execute malicious scripts in the context of users who are deceived into interacting with a crafted link. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.
Original NVD Description
The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action.