Description
WordPress Plugin Link Library is prone to an SQL injection and a cross-site scripting vulnerability. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Link Library version 5.0.8 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 5.0.9 or latest
References
Related Vulnerabilities
WordPress Plugin Cashtomer SQL Injection (1.0.0)
WordPress 2.5 Cookie Integrity Protection Unauthorized Access Vulnerability (0.6.2 - 2.5)
WordPress Plugin WassUp Real Time Analytics Cross-Site Scripting (1.8.3)
PHP Out-of-bounds Read Vulnerability (CVE-2020-7064)
WordPress Plugin Import Spreadsheets from Microsoft Excel Arbitrary File Upload (10.1.4)