{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ano_external_links_projectno_external_linkswordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:no_external_links_project:no_external_links:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-95670"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["No External Links (\u003c= 5.2.0)"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","web-application","vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe 'No External Links' plugin for WordPress, in all versions up to and including 5.2.0, contains a Stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from insufficient input sanitization and output escaping within the plugin's URL logging functionality. Specifically, the vulnerability resides in the /goto/ redirect mechanism when the 'Link Encoding: Base64' setting is enabled by an administrator. An unauthenticated attacker can craft a malicious URL containing a Base64-encoded JavaScript payload and trigger the storage of this script within the site's logs. When a user - such as an administrator - subsequently views the affected page or logs, the injected script executes in the context of the victim's browser. This could lead to session hijacking, unauthorized actions on behalf of the user, or further site compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. Depending on the privileges of the victim viewing the logs, this could result in account takeover, defacement, or the injection of additional malicious content into the WordPress site. Given the plugin's function to manage external links, this vulnerability poses a significant risk to site integrity and user data privacy.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'No External Links' plugin to the latest version (patch version \u0026gt; 5.2.0) immediately.\u003c/li\u003e\n\u003cli\u003eDisable the 'Link Encoding: Base64' feature within the plugin settings until a patch is applied if immediate upgrading is not feasible.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous requests to the '/goto/' directory containing Base64 strings.\u003c/li\u003e\n\u003cli\u003eImplement a strong Content Security Policy (CSP) to mitigate the impact of potential XSS attacks by restricting the execution of inline scripts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T08:23:54Z","date_published":"2026-10-02T08:23:54Z","id":"https://feed.craftedsignal.io/briefs/2026-10-no-external-links-xss/","summary":"The No External Links WordPress plugin (\u003c= 5.2.0) is vulnerable to Stored Cross-Site Scripting (XSS) via the /goto/ redirect feature, allowing unauthenticated attackers to inject malicious scripts.","title":"Stored XSS Vulnerability in No External Links WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-no-external-links-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:no_external_links_project:no_external_links:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}