VYPR
Medium severity6.5NVD Advisory· Published Oct 27, 2025· Updated Apr 27, 2026

CVE-2025-62898

CVE-2025-62898

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maarten Links shortcode links-shortcode allows Stored XSS.This issue affects Links shortcode: from n/a through <= 1.8.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in WordPress Links shortcode plugin (≤1.8.3) allows attackers to inject malicious scripts, potentially used in mass exploitation campaigns.

Vulnerability

The WordPress Links shortcode plugin (versions up to and including 1.8.3) contains a stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation [1]. This allows an attacker to inject arbitrary web scripts into pages that will be executed when other users visit the site.

Exploitation

Exploitation requires that a user with at least contributor-level privileges interacts with a crafted link or page [1]. The vulnerability can be initiated by a privileged user, but successful execution depends on additional user interaction, such as clicking a malicious link or submitting a form [1]. This type of vulnerability is frequently used in mass-exploit campaigns targeting thousands of WordPress sites.

Impact

An attacker can inject malicious scripts, including redirects, advertisements, and other HTML payloads [1]. These scripts execute in the context of the victim's browser, potentially leading to credential theft, site defacement, or further compromise of the WordPress installation.

Mitigation

Users are strongly advised to update the Links shortcode plugin to a version newer than 1.8.3 as soon as possible [1]. If unable to update, contact your hosting provider or web developer for assistance. Patchstack has identified this vulnerability and recommends immediate action due to its potential for mass exploitation.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.