Sceawere
Vulnerability Detail
CVE-2026-95670UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
No External Links Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 15h ago
- Vendor
- mihdan
- Product
- No External Links
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has enabled the 'Link Encoding: Base64' option in the plugin settings.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T08:17:03.760Z",
"pubdate": "2026-10-02T08:17:03.760Z",
"executiveSummary": "The No External Links plugin for WordPress, in versions up to and including 5.2.0, contains a Stored Cross-Site Scripting (XSS) vulnerability.\nThe flaw originates from insufficient sanitization of input processed through the /goto/{base64} redirect functionality.\nThis vulnerability allows unauthenticated remote attackers to inject malicious JavaScript into the application, which executes within the browser context of any user visiting the compromised page.\nThe exploit specifically requires the 'Link Encoding: Base64' option to be enabled by an administrator within the plugin settings.\nSuccessful exploitation poses a significant security risk, as it enables unauthorized script execution, potential session hijacking, unauthorized actions on behalf of the user, and the manipulation of displayed page content.\nGiven the nature of the injection, the impact is critical for both the integrity and confidentiality of the affected WordPress site's front-end interactions.",
"technicalDetails": "The root cause of this vulnerability is the failure of the plugin to properly sanitize input data and escape output when processing redirect requests via the /goto/ endpoint. When the 'Link Encoding: Base64' feature is active, the plugin attempts to decode base64 strings provided in the URL path to facilitate redirection.\nBecause the plugin does not adequately validate the content of the decoded input, an attacker can supply a specially crafted base64-encoded string containing malicious JavaScript payloads. The application subsequently reflects this decoded, unescaped string back into the HTML response, leading to stored XSS.\nThe attack flow begins when an attacker identifies the /goto/ redirect structure. The attacker generates a malicious payload containing an XSS vector (e.g., <script>alert(document.cookie)</script>). This payload is base64 encoded to conform to the expected input format of the /goto/ URI handler. The attacker then triggers a request to the server with this encoded string.\nIf the 'Link Encoding: Base64' setting is enabled, the plugin decodes the input and embeds the resulting malicious script directly into the response page. Since the script is stored and rendered upon page access, the payload executes whenever a victim, such as an administrator or a standard user, visits the injected URL or is directed to a page where the decoded input is rendered.\nThe impact of this XSS vulnerability includes, but is not limited to, the theft of sensitive session cookies, the redirection of users to malicious third-party websites, the unauthorized performance of administrative actions via Cross-Site Request Forgery (CSRF) triggered through the XSS, and the modification of the visual appearance of the affected web page to conduct phishing attacks.\nThe vulnerability is accessible to unauthenticated attackers because the redirect handler does not require active session authentication. The lack of input validation on the redirect target makes the system inherently susceptible to arbitrary code injection. Post-exploitation, an attacker gains the ability to manipulate the Document Object Model (DOM) of the user's browser, enabling full control over the user's interaction with the site within the context of that specific session."
}