CPE
The No External Links WordPress plugin (<= 5.2.0) is vulnerable to Stored Cross-Site Scripting (XSS) via the /goto/ redirect feature, allowing unauthenticated attackers to inject malicious scripts.