PT-2026-43636 · WordPress · Minhnhut Link Gateway
San6051
·
Published
2026-05-27
·
Updated
2026-05-27
·
CVE-2026-3349
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MinhNhut Link Gateway versions prior to 3.6.2
Description
The MinhNhut Link Gateway plugin for WordPress contains a Reflected Cross-Site Scripting issue. This occurs due to insufficient input sanitization and output escaping of the
url parameter on the redirect page. Unauthenticated attackers can exploit this by tricking a user into clicking a link, allowing the injection and execution of arbitrary web scripts in the user's browser.Recommendations
Update the plugin to a version newer than 3.6.1.
As a temporary workaround, restrict or sanitize the use of the
url parameter on the redirect page.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minhnhut Link Gateway