high · CVSS v3 7.2 · EPSS 0.00241
CVE-2026-95670
The No External Links WordPress plugin (v5.2.0 and earlier) contains a stored XSS flaw that can be triggered via a /goto/{base64} redirect w
Overview
The No External Links WordPress plugin (v5.2.0 and earlier) contains a stored XSS flaw that can be triggered via a /goto/{base64} redirect when the admin has enabled Base64 link encoding. Unauthenticated attackers can inject scripts that execute for any user visiting the affected page. This vulnerability can lead to session hijacking, defacement, or data theft.
Description
The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has enabled the 'Link Encoding: Base64' option in the plugin settings.
Impact
The flaw allows attackers to inject malicious scripts into stored content, compromising confidentiality by exfiltrating data, integrity by modifying page content, and availability if scripts disrupt site functionality. Site administrators and end‑users who view the affected pages are at risk.
Remediation
Update the No External Links plugin to the latest version (5.2.1 or newer) where the XSS issue is fixed. If an update is not immediately possible, disable the 'Link Encoding: Base64' option or remove the plugin entirely. Additionally, ensure that all user‑generated content is properly sanitized and escaped on output.
Risk context
Severity is high with a CVSS v3 score of 7.2 and an EPSS of 0.00241, indicating a low probability of exploitation but a significant impact if exploited. Defenders should prioritize patching or disabling the plugin to mitigate potential attacks.
Affected products
- WordPress No External Links 5.2.0
- WordPress No External Links 5.1.x
- WordPress No External Links 5.0.x
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00241