PT-2026-43634 · WordPress · Mylinksdump

San6051

·

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-2288

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions myLinksDump versions prior to 1.7
Description The myLinksDump plugin for WordPress contains a Stored Cross-Site Scripting issue caused by insufficient input sanitization and output escaping. This allows authenticated attackers with administrator-level access or higher to inject arbitrary web scripts into pages, which then execute when a user visits the affected page. This issue specifically impacts multi-site installations and environments where unfiltered html has been disabled. The flaw is triggered via the link title parameter.
Recommendations Update to a version later than 1.6. As a temporary mitigation, restrict administrator-level access or ensure unfiltered html is managed according to security policies to minimize the risk of script injection via the link title parameter.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-2288

Affected Products

Mylinksdump