<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>No External Links (&lt;= 5.2.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/no-external-links--5.2.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 08:23:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/no-external-links--5.2.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS Vulnerability in No External Links WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-no-external-links-xss/</link><pubDate>Fri, 02 Oct 2026 08:23:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-no-external-links-xss/</guid><description>The No External Links WordPress plugin (&lt;= 5.2.0) is vulnerable to Stored Cross-Site Scripting (XSS) via the /goto/ redirect feature, allowing unauthenticated attackers to inject malicious scripts.</description><content:encoded><![CDATA[<p>The 'No External Links' plugin for WordPress, in all versions up to and including 5.2.0, contains a Stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from insufficient input sanitization and output escaping within the plugin's URL logging functionality. Specifically, the vulnerability resides in the /goto/ redirect mechanism when the 'Link Encoding: Base64' setting is enabled by an administrator. An unauthenticated attacker can craft a malicious URL containing a Base64-encoded JavaScript payload and trigger the storage of this script within the site's logs. When a user - such as an administrator - subsequently views the affected page or logs, the injected script executes in the context of the victim's browser. This could lead to session hijacking, unauthorized actions on behalf of the user, or further site compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. Depending on the privileges of the victim viewing the logs, this could result in account takeover, defacement, or the injection of additional malicious content into the WordPress site. Given the plugin's function to manage external links, this vulnerability poses a significant risk to site integrity and user data privacy.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the 'No External Links' plugin to the latest version (patch version &gt; 5.2.0) immediately.</li>
<li>Disable the 'Link Encoding: Base64' feature within the plugin settings until a patch is applied if immediate upgrading is not feasible.</li>
<li>Monitor webserver access logs for anomalous requests to the '/goto/' directory containing Base64 strings.</li>
<li>Implement a strong Content Security Policy (CSP) to mitigate the impact of potential XSS attacks by restricting the execution of inline scripts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>xss</category><category>web-application</category><category>vulnerability</category></item></channel></rss>