Linkwhisper
Linkwhisper Link Whisper Free: vulnerabilidades y CVE
Linkwhisper Link Whisper Free tiene 13 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-14601 | Media (6.8) | 0.39% | — | 21 ago 2026 | The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection… |
| CVE-2026-57333 | Alta (7.1) | 0.25% | — | 29 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions. |
| CVE-2025-11262 | Alta (7.2) | 0.24% | — | 29 may 2026 | The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 due to insufficient input sanitization and output escaping.… |
| CVE-2026-22357 | Alta (7.1) | 0.19% | — | 20 feb 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a… |
| CVE-2025-67927 | Alta (7.1) | 0.22% | — | 8 ene 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a… |
| CVE-2025-11263 | Media (6.1) | 0.21% | — | 6 dic 2025 | The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all versions up to, and including, 0.8.8 due to insufficient input sanitization and output escaping.… |
| CVE-2025-62970 | Media (5.3) | 0.22% | — | 27 oct 2025 | Missing Authorization vulnerability in Spencer Haws Link Whisper Free link-whisper allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Link Whisper Free: from n/a through <= 0.9.2. |
| CVE-2025-22306 | Media (5.3) | 0.36% | — | 7 ene 2025 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Spencer Haws Link Whisper Free link-whisper.This issue affects Link Whisper Free: from n/a through <= 0.7.7. |
| CVE-2023-32506 | Media (6.5) | 0.47% | — | 13 dic 2024 | Missing Authorization vulnerability in Link Whisper Link Whisper Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Link Whisper Free: from n/a through 0.6.3. |
| CVE-2024-31934 | Media (4.3) | 0.21% | — | 11 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.9. |
| CVE-2024-27992 | Alta (7.1) | 0.39% | — | 11 abr 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Whisper Link Whisper Free allows Reflected XSS.This issue affects Link Whisper Free: from n/a through 0.6.8. |
| CVE-2024-2693 | Alta (8.8) | 0.81% | — | 9 abr 2024 | The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.7.1 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it… |
| CVE-2023-47852 | Alta (7.2) | 0.56% | — | 20 dic 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.5. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.