The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action. This CVE record was published on 2026-08-08T07:17:10.013Z. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM sever [truncated]
The Link Library WordPress plugin before version 7.9.3 is vulnerable to SQL injection attacks due to improper sanitization and escaping of user-supplied values used in SQL queries. This could allow unauthenticated users to perform malicious database queries. The vulnerability's technical impact is related to the potential for data breaches or unauthorized database modifications. Affected systems may inclu [truncated]