← back to popular plugins
wordfence / plugin · link-whisper
Link Whisper Free
link-whisper
total installs
30,000
total vulns
6
critical
0
high
0
medium
6
low
0
latest vuln
—
patched
5
unpatched
1
avg time to patch
—
vulnerabilities
(6)
Link Whisper Free < 0.9.1 - Missing Authorization to Unauthenticated Settings Change
medium
✓ patched
The Link Whisper Free plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 0.9.1 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
Link Whisper Free <= 0.9.2 - Reflected Cross-Site Scripting
medium
✓ patched
cve id
CVE-2026-22357 ↗
cvss score
6.1
cwe
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published
Feb 16, 2026
The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting
medium
✓ patched
cve id
CVE-2025-67927 ↗
cvss score
6.1
cwe
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published
Jan 5, 2026
The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting
medium
✓ patched
cve id
CVE-2025-11263 ↗
cvss score
6.1
cwe
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published
Dec 5, 2025
The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all versions up to, and including, 0.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Link Whisper Free <= 0.8.8 - Missing Authorization
medium
✕ unpatched
The Link Whisper Free plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 0.8.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Link Whisper Free <= 0.7.8 - Unauthenticated Sensitive Information Exposure
medium
✓ patched
cve id
CVE-2025-22306 ↗
cvss score
5.3
cwe
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
published
Jan 6, 2025
The Link Whisper Free plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.7.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.