Junglewise Threat Intelligence

CVE-2026-3348: MinhNhut Link Gateway Stored XSS in plugin settings

CVE-2026-3348 · Severity: medium · CVSS 4.4 · Published 2026-05-27

Executive brief

The MinhNhut Link Gateway plugin for WordPress, which manages link redirection and gateway pages, contains a security flaw that allows administrators to embed malicious scripts into the plugin settings. If exploited, these scripts could execute in the browsers of users visiting the site's redirect pages, potentially leading to unauthorized actions or data theft. This issue primarily impacts WordPress multi-site environments or specific configurations where standard security restrictions on HTML content have been tightened.

Technical details

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the plugin's settings fields, such as Title and Description. An authenticated attacker with Administrator-level privileges can inject arbitrary web scripts into these fields. These scripts are then stored and executed in the context of any user's browser who visits the affected redirect pages. This vulnerability specifically impacts WordPress multi-site installations or single-site installations where the 'unfiltered_html' capability has been disabled for administrators. The issue exists in all versions up to and including 3.6.1.

Affected products

  • MinhNhut MinhNhut Link Gateway up to, and including, 3.6.1

Timeline

  • 2026-05-27: disclosed

References

Related threats