Beta

Report

Pz-LinkCard <= 2.4.5.2 is vulnerable to Reflected Cross-Site Scripting (XSS) vulnerability

Unauthenticated
Published
2022-02-28

The Pz-LinkCard plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS

Score:6.1

Severity:Medium

Version: 2.4.5.2

There is a patch available in v2.4.5.3 and we strongly recommend you update to this version as soon as possible.