The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header.Referenceshttps://wpvulndb.com/vulnerabilities/8015https://wordpress.org/plugins/incoming-links/#developershttps://plugins.trac.wordpress.org/changeset/1080044/incoming-links