CVE-2021-25091: Link Library < 7.2.9 - Reflected Cross-Site Scripting
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-25091?
CVE-2021-25091 is classified as a medium severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2021-25091?
To fix CVE-2021-25091, update the Link Library WordPress plugin to version 7.2.9 or later as it includes the necessary sanitization and escaping measures.
Who is affected by CVE-2021-25091?
CVE-2021-25091 affects users of the Link Library WordPress plugin prior to version 7.2.9.
What type of vulnerability is CVE-2021-25091?
CVE-2021-25091 is a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2021-25091 be exploited without authentication?
Yes, CVE-2021-25091 can be exploited without authentication, allowing an attacker to execute scripts in the context of the affected admin page.