BetterLinks <= 3.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Short URL Creation via create_fbs_link AJAX Action
medium
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for aut...
- CVSS:
- 4.3
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.1
- Disclosed:
- Aug 24, 2026
CVE-2026-19801 on NVD →
BetterLinks <= 2.1.7 - Authenticated (Administrator+) SQL Injection
medium
The BetterLinks plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and a...
- CVSS:
- 4.9
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.8
- Disclosed:
- Nov 1, 2024
CVE-2024-51672 on NVD →
BetterLinks <= 1.6.0 - Improper Authorization to Data Import and Export
medium
The BetterLinks plugin for WordPress is vulnerable to unauthorized access and modification due to insufficient capability checks on the import_data and export_data functions in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to import and export plugin data.
- CVSS:
- 6.5
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.1
- Disclosed:
- Oct 18, 2023
CVE-2023-45104 on NVD →
BetterLinks – Shorten, Track and Manage any URL <= 1.2.5 - Stored Cross-Site Scripting
medium
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.
- CVSS:
- 5.4
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Oct 20, 2021
CVE-2021-24812 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database