WordPress 插件 Link Library 在 7.9.6 版本之前存在安全漏洞。当插件发起的安全请求被拒绝时,它会回退到一个未受保护的获取方式,但未对用户提供的 URL 目标进行验证。这使得未认证的访问者能够利用该站点向内部网络中的主机发起请求,并通过响应内容判断内部服务是否活跃,从而泄露内网信息。 版本低于 7.8.8 的受此漏洞影响(CVE-2025-68600 已覆盖该范围);本条目描述的是 7.8.8 至 7.9.5 版本,在这些版本中此前修复不完整。要利用此漏洞,网站管理员必须已启用反向链接验证
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Link Library | 7.8.8 ~ 7.9.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80514 | 5.3 MEDIUM | wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass |
| CVE-2026-86837 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass |
| CVE-2026-88848 | 4.2 MEDIUM | MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restrictio |
| CVE-2026-78394 | Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter | |
| CVE-2026-78393 | Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb |
No comments yet