CVE-2025-46237: WordPress Link Library plugin <= 7.8 - Cross Site Scripting (XSS) Vulnerability
Published Apr 22, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Stored XSS.This issue affects Link Library: from n/a through <= 7.8.
Affected Software
3 affected components
Yannick Lefebvre Link Library<=7.8
WordPress Link Library<=7.8
Ylefebvre Link Library Wordpress<7.8.1
Remediation
Information
Update the WordPress Link Library plugin to the latest available version (at least 7.8.1).
Event History
Apr 22, 2025
CVE Published
via MITRE·09:53 AM
Data Sourced
via MITRE·09:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-46237?
CVE-2025-46237 has a high severity due to its potential for allowing stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-46237?
To fix CVE-2025-46237, upgrade the Yannick Lefebvre Link Library to the latest version above 7.8.
3
Who is affected by CVE-2025-46237?
CVE-2025-46237 affects all versions of the Yannick Lefebvre Link Library from n/a through 7.8.
4
What type of vulnerability is CVE-2025-46237?
CVE-2025-46237 is a Stored Cross-site Scripting (XSS) vulnerability.
5
What can attackers do with CVE-2025-46237?
Attackers exploiting CVE-2025-46237 can inject malicious scripts that may be executed in the context of users accessing the affected application.