Junglewise Threat Intelligence

CVE-2026-8842: Google+ Link Name WordPress plugin Stored XSS in gplusnamelink shortcode

CVE-2026-8842 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Executive brief

The Google+ Link Name plugin for WordPress, which allows users to display Google+ profile links, contains a security flaw that allows attackers to inject malicious scripts into website pages. An attacker with basic contributor-level access can use this vulnerability to run unauthorized code in the browsers of site visitors or administrators. This could lead to unauthorized actions being performed on the site, theft of session information, or redirection of users to malicious websites.

Technical details

The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the gplusnamelink_generate() function. Specifically, the 'id' and 'name' attributes of the 'gplusnamelink' shortcode are concatenated directly into the rendered HTML without being processed by security functions like esc_attr() or esc_html(). This allows authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts into pages. These scripts will execute in the context of any user's browser who views the affected page. The vulnerability exists in all versions up to and including 1.0.

Affected products

  • Google+ Link Name plugin for WordPress team Google+ Link Name up to, and including, 1.0

Timeline

  • 2026-05-27: disclosed: Vulnerability published in NVD dataset
  • 2026-05-27: advisory: Wordfence published security advisory

References