CVE-2025-11263
- EPSS 0.21%
- Veröffentlicht 06.12.2025 03:27:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all versions up to, and including, 0.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unaut...
CVE-2025-22306
- EPSS 0.1%
- Veröffentlicht 07.01.2025 17:15:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Spencer Haws Link Whisper Free link-whisper.This issue affects Link Whisper Free: from n/a through <= 0.7.7.
CVE-2023-32506
- EPSS 0.17%
- Veröffentlicht 13.12.2024 15:15:11
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in Link Whisper Link Whisper Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Link Whisper Free: from n/a through 0.6.3.
CVE-2024-31934
- EPSS 0.2%
- Veröffentlicht 11.04.2024 13:15:54
- Zuletzt bearbeitet 15.04.2026 00:35:42
Cross-Site Request Forgery (CSRF) vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.9.
CVE-2024-27992
- EPSS 0.24%
- Veröffentlicht 11.04.2024 01:25:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Whisper Link Whisper Free allows Reflected XSS.This issue affects Link Whisper Free: from n/a through 0.6.8.
CVE-2024-2693
- EPSS 0.83%
- Veröffentlicht 09.04.2024 19:15:36
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.7.1 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated atta...
CVE-2023-47852
- EPSS 0.12%
- Veröffentlicht 20.12.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:54
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.5.