rootpwn

high · CVSS v3 7.2 · EPSS 0.00241

CVE-2026-95670

The No External Links WordPress plugin (v5.2.0 and earlier) contains a stored XSS flaw that can be triggered via a /goto/{base64} redirect w

Overview

The No External Links WordPress plugin (v5.2.0 and earlier) contains a stored XSS flaw that can be triggered via a /goto/{base64} redirect when the admin has enabled Base64 link encoding. Unauthenticated attackers can inject scripts that execute for any user visiting the affected page. This vulnerability can lead to session hijacking, defacement, or data theft.

Description

The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has enabled the 'Link Encoding: Base64' option in the plugin settings.

Impact

The flaw allows attackers to inject malicious scripts into stored content, compromising confidentiality by exfiltrating data, integrity by modifying page content, and availability if scripts disrupt site functionality. Site administrators and end‑users who view the affected pages are at risk.

Remediation

Update the No External Links plugin to the latest version (5.2.1 or newer) where the XSS issue is fixed. If an update is not immediately possible, disable the 'Link Encoding: Base64' option or remove the plugin entirely. Additionally, ensure that all user‑generated content is properly sanitized and escaped on output.

Risk context

Severity is high with a CVSS v3 score of 7.2 and an EPSS of 0.00241, indicating a low probability of exploitation but a significant impact if exploited. Defenders should prioritize patching or disabling the plugin to mitigate potential attacks.

Affected products

  • WordPress No External Links 5.2.0
  • WordPress No External Links 5.1.x
  • WordPress No External Links 5.0.x

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00241

wordpress plugin xss stored base64

← All CVEs