CVE-2025-11263
- EPSS 0.13%
- Veröffentlicht 06.12.2025 03:27:04
- Zuletzt bearbeitet 08.12.2025 18:26:49
The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all versions up to, and including, 0.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unaut...
CVE-2025-22306
- EPSS 0.19%
- Veröffentlicht 07.01.2025 17:15:32
- Zuletzt bearbeitet 07.01.2025 17:15:32
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.7.7.
CVE-2023-32506
- EPSS 0.17%
- Veröffentlicht 13.12.2024 15:15:11
- Zuletzt bearbeitet 13.12.2024 15:15:11
Missing Authorization vulnerability in Link Whisper Link Whisper Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Link Whisper Free: from n/a through 0.6.3.
CVE-2024-31934
- EPSS 0.2%
- Veröffentlicht 11.04.2024 13:15:54
- Zuletzt bearbeitet 21.11.2024 09:14:09
Cross-Site Request Forgery (CSRF) vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.9.
CVE-2024-27992
- EPSS 0.24%
- Veröffentlicht 11.04.2024 01:25:08
- Zuletzt bearbeitet 21.11.2024 09:05:34
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Whisper Link Whisper Free allows Reflected XSS.This issue affects Link Whisper Free: from n/a through 0.6.8.
CVE-2024-2693
- EPSS 0.83%
- Veröffentlicht 09.04.2024 19:15:36
- Zuletzt bearbeitet 21.11.2024 09:10:18
The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.7.1 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated atta...
CVE-2023-47852
- EPSS 0.12%
- Veröffentlicht 20.12.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:54
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.5.