elink – Embed Content <= 1.1.0 - Authenticated (Contributor+) Insufficient Input Validation

2025-08-14 20:11
Shreyas Malhotra

Strategic Overview

Status
Unpatched
Affected Version<= 1.1.0
CVSS6.4Medium
CVECVE-2025-7507
View all elink – Embed Content vulnerabilities

Vulnerability Overview

The elink – Embed Content plugin for WordPress is vulnerable to Malicious Redirect in all versions up to, and including, 1.1.0. This is due to the plugin not restricting URLS that can be supplied through the elink shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to supply an HTML file that can be leverged to redirect users to a malicious domain.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C