PT-2026-43636 · WordPress · Minhnhut Link Gateway

San6051

·

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-3349

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MinhNhut Link Gateway versions prior to 3.6.2
Description The MinhNhut Link Gateway plugin for WordPress contains a Reflected Cross-Site Scripting issue. This occurs due to insufficient input sanitization and output escaping of the url parameter on the redirect page. Unauthenticated attackers can exploit this by tricking a user into clicking a link, allowing the injection and execution of arbitrary web scripts in the user's browser.
Recommendations Update the plugin to a version newer than 3.6.1. As a temporary workaround, restrict or sanitize the use of the url parameter on the redirect page.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-3349

Affected Products

Minhnhut Link Gateway