{"id":"CVE-2026-78393","title":"The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could…","summary":"The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could…","severity":"none","cwe":["CWE-79"],"product":"Link Library","affected":["link_library < 7.9.6"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T07:16:54.327","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78393","references":[{"url":"https://wpscan.com/vulnerability/2605888a-195d-4bce-8aac-347710ad1de8/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T07:01:12.116Z","slug":"CVE-2026-78393","body":"## Overview\n\nThe Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could be used against any visitor, including logged-in administrators.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}