CVE-2026-16535 - Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel
CVE ID :CVE-2026-16535
Published : Aug. 8, 2026, 6 a.m. | 1 hour, 27 minutes ago
Description :The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 8, 2026, 6 a.m. | 1 hour, 27 minutes ago
Description :The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...