CVE-2025-2889

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Apr 5, 2025
Updated: Apr 7, 2025
CWE ID 94

Summary

CVE-2025-2889 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Link Library plugin in WordPress. This issue, present in all versions up to 7.7.3, allows authenticated attackers with Contributor-level access or higher to inject malicious scripts. The vulnerability arises from insufficient sanitization and output escaping of input in the Link Additional Parameters feature. Successful exploitation enables attackers to execute arbitrary web scripts on pages, posing a significant security risk for WordPress sites. Upgrading to the latest version of the Link Library plugin is strongly recommended to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share