在 7.9.6 版本之前的 Link Library WordPress 插件在前端目录页面生成链接时,未对部分参数进行适当的转义处理,导致反射型跨站脚本攻击(Reflected Cross-Site Scripting)。该漏洞可能被攻击者利用,针对任何网站访问者(包括已登录的管理员)实施攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Link Library | 0 ~ 7.9.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80514 | 5.3 MEDIUM | wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass |
| CVE-2026-86837 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass |
| CVE-2026-88848 | 4.2 MEDIUM | MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restrictio |
| CVE-2026-78394 | Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter | |
| CVE-2026-78397 | Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation |
No comments yet