CVE-2024-35687 – WordPress Link Library plugin <= 7.6.3 - Reflected Cross-Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2024-35687
06 Jun 2024 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.3. La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web (XSS o 'Cross-site Scripting') en Yannick Lefebvre Link Library link-library permite el XSS reflejado. Este problema afecta a la librería de enlaces: desde n/a hasta 7.6.3. The Link Li... • https://patchstack.com/database/vulnerability/link-library/wordpress-link-library-plugin-7-6-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-4199 – Link Library < 7.4.1 - Admin+ Stored XSS
https://notcve.org/view.php?id=CVE-2022-4199
23 Dec 2022 — The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). El complemento Link Library de WordPress anterior a 7.4.1 no sanitiza ni escapa algunas de sus configuraciones, lo que podría permitir a usuarios con privilegios elevados, como el administrador, realizar ataques de cross site... • https://wpscan.com/vulnerability/c4688c0b-0538-4151-995c-d437d7e4829d • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-25092 – Link Library < 7.2.8 - Library Settings Reset via CSRF
https://notcve.org/view.php?id=CVE-2021-25092
30 Dec 2021 — The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack El plugin Link Library de WordPress versiones anteriores a 7.2.8, no presenta una comprobación de tipo CSRF cuando es restablecida la configuración de la biblioteca, permitiendo a atacantes hacer que un administrador conectado restablezca configuraciones arbitrarias por medio de un ataque de tipo CSRF • https://wpscan.com/vulnerability/1cd30913-67c7-46c3-a2de-dcca0c332323 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-25091 – Link Library < 7.2.9 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-25091
30 Dec 2021 — The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting El plugin Link Library de WordPress versiones anteriores a 7.2.9, no sanea y escapa del parámetro settingscopy antes de devolverlo a una página de administración, conllevando a un ataque de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/96204946-0b10-4a2c-8079-473883ff95b6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-25093 – Link Library < 7.2.8 - Unauthenticated Arbitrary Links Deletion
https://notcve.org/view.php?id=CVE-2021-25093
30 Dec 2021 — The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request El plugin Link Library de WordPress versiones anteriores a 7.2.8, no dispone de autorización cuando se eliminan enlaces, permitiendo a usuarios no autenticados eliminar enlaces arbitrarios por medio de una petición diseñada • https://wpscan.com/vulnerability/7a7603ce-d76d-4c49-a886-67653bed8cd3 • CWE-862: Missing Authorization •