CVE-2026-78393: Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb Links
The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could be used against any visitor, including logged-in administrators.
Affected Software
Event History
Frequently Asked Questions
Which visitors are at risk?
Any visitor to affected front-end directory pages can be targeted, including logged-in WordPress administrators. The issue is reflected XSS, so an attacker would need to cause a victim to visit a crafted link.
Which parameters are involved in the attack?
The affected parameters are link_tags and link_price. They are insufficiently escaped when included in addresses generated for sort and breadcrumb links on front-end directory pages.
What versions should be remediated?
Link Library versions before 7.9.6 are affected. Update to version 7.9.6 or later.