PT-2026-43509 · Morettolss+1 · Google+ Link Name+1
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Google+ Link Name plugin for WordPress versions prior to 1.1
Description
Stored Cross-Site Scripting occurs via the
gplusnamelink shortcode. The issue stems from insufficient input sanitization and output escaping within the gplusnamelink generate() function. Specifically, the id and name variables are concatenated directly into the rendered HTML without using esc attr() or esc html(). This allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which execute when a user visits the affected page.Recommendations
Update the plugin to a version later than 1.0.
As a temporary mitigation, restrict user permissions to prevent users with contributor-level access from editing pages or using the
gplusnamelink shortcode.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google+ Link Name
Google-Plus-Name-Link-Popup-Badge