CVE-2026-78393: Unknown Link Library

Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.

The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could be used against any visitor, including logged-in administrators.

Affected products

  • Unknown Link Library: before 7.9.6 (fixed in 7.9.6)

Published 2026-09-25. Last modified 2026-09-25.