Medium 6.4 Unfixed
2026-04-18≤ 2.5.8.1
Pz-LinkCard <= 2.5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Minimum safe version
2.5.7
Update to 2.5.7 or later to address 6 fixable vulnerabilities
Pz-LinkCard <= 2.5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
WordPress Pz-LinkCard Plugin < 2.5.7 is vulnerable to Server Side Request Forgery (SSRF)
CVE-2024-0672
CVE-2024-0677
CVE-2024-0673
CVE-2023-47790
CVE-2021-25012