PT-2026-43634 · WordPress · Mylinksdump
San6051
·
Published
2026-05-27
·
Updated
2026-05-27
·
CVE-2026-2288
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
myLinksDump versions prior to 1.7
Description
The myLinksDump plugin for WordPress contains a Stored Cross-Site Scripting issue caused by insufficient input sanitization and output escaping. This allows authenticated attackers with administrator-level access or higher to inject arbitrary web scripts into pages, which then execute when a user visits the affected page. This issue specifically impacts multi-site installations and environments where
unfiltered html has been disabled. The flaw is triggered via the link title parameter.Recommendations
Update to a version later than 1.6.
As a temporary mitigation, restrict administrator-level access or ensure
unfiltered html is managed according to security policies to minimize the risk of script injection via the link title parameter.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mylinksdump