Executive brief
Link Whisper Free is a WordPress plugin used to manage internal linking for SEO purposes. A security vulnerability in versions 0.9.4 and earlier allows unauthenticated attackers to perform Cross-Site Scripting (XSS) attacks. If a privileged user (such as an administrator) clicks a malicious link, an attacker could execute unauthorized scripts in their browser, potentially leading to website defacement, unauthorized redirects, or administrative account takeover.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Link Whisper Free plugin for WordPress (versions <= 0.9.4) due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability can be exploited by an unauthenticated remote attacker by tricking a site visitor or administrator into clicking a specially crafted link. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to the theft of session cookies or the performance of administrative actions on behalf of the victim. The issue is resolved in version 0.9.5.
Affected products
- Spencer Haws (Link Whisper INC) Link Whisper Free <= 0.9.4
Timeline
- 2026-05-08: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
- 2026-06-29: disclosed: Public disclosure and CVE assignment
- 2026-06-29: patched: Patch released in version 0.9.5