What is CVE-2026-16535?
The Link Library WordPress plugin before version 7.9.4 fails to sanitise and escape a parameter before reflecting it in the response. This vulnerability allows unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users tricked into performing an action. Users should update the plugin immediately.
Azərbaycanca: Link Library WordPress plagini (7.9.4-dən əvvəlki versiyalar) istifadəçi parametrlərini düzgün sanitizə etmir və cavabda olduğu kimi əks etdirir. Bu zəiflik autentifikasiya olunmamış hücumçulara Reflected XSS hücumları həyata keçirməyə imkan verir. İstifadəçilər plagini dərhal ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
What security flaw does CVE-2026-16535 describe in the Link Library plugin?
The flaw allows unauthenticated attackers to perform Reflected Cross-Site Scripting attacks because the plugin fails to sanitise and escape a parameter before reflecting it in the response.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.