← back to popular plugins
wordfence / plugin · link-whisper

Link Whisper Free

link-whisper
total installs
30,000
total vulns
6
critical
0
high
0
medium
6
low
0
latest vuln
patched
5
unpatched
1
avg time to patch
vulnerabilities (6)
Link Whisper Free < 0.9.1 - Missing Authorization to Unauthenticated Settings Change
medium ✓ patched
cvss score 5.3
cwe CWE-862: Missing Authorization
published Apr 7, 2026
The Link Whisper Free plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 0.9.1 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
Link Whisper Free <= 0.9.2 - Reflected Cross-Site Scripting
medium ✓ patched
cvss score 6.1
cwe CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published Feb 16, 2026
The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting
medium ✓ patched
cvss score 6.1
cwe CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published Jan 5, 2026
The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting
medium ✓ patched
cvss score 6.1
cwe CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published Dec 5, 2025
The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all versions up to, and including, 0.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Link Whisper Free <= 0.8.8 - Missing Authorization
medium ✕ unpatched
cvss score 5.3
cwe CWE-862: Missing Authorization
published Oct 18, 2025
The Link Whisper Free plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 0.8.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Link Whisper Free <= 0.7.8 - Unauthenticated Sensitive Information Exposure
medium ✓ patched
cvss score 5.3
cwe CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
published Jan 6, 2025
The Link Whisper Free plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.7.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.