Loading market data...
← Back to CVE feed

CVE-2026-16535

UNKNOWN View on NVD ↗

Description

The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action.

Published: Aug 08, 2026 07:17 UTC Modified: Aug 08, 2026 07:17 UTC