plugin

Betterlinks Vulnerabilities

4 known security issues reported for the Betterlinks WordPress plugin. Most recent disclosed Aug 24, 2026.

4 medium

Running Betterlinks on your site? Check whether your installed version is affected.

Scan your site free

BetterLinks <= 3.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Short URL Creation via create_fbs_link AJAX Action

medium

The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for aut...

CVSS:
4.3
Affected:
up to 3.1.0
Fixed in:
3.1.1
Disclosed:
Aug 24, 2026

CVE-2026-19801 on NVD →

BetterLinks <= 2.1.7 - Authenticated (Administrator+) SQL Injection

medium

The BetterLinks plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and a...

CVSS:
4.9
Affected:
up to 2.1.7
Fixed in:
2.1.8
Disclosed:
Nov 1, 2024

CVE-2024-51672 on NVD →

BetterLinks <= 1.6.0 - Improper Authorization to Data Import and Export

medium

The BetterLinks plugin for WordPress is vulnerable to unauthorized access and modification due to insufficient capability checks on the import_data and export_data functions in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to import and export plugin data.

CVSS:
6.5
Affected:
up to 1.6.0
Fixed in:
1.6.1
Disclosed:
Oct 18, 2023

CVE-2023-45104 on NVD →

BetterLinks – Shorten, Track and Manage any URL <= 1.2.5 - Stored Cross-Site Scripting

medium

The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.

CVSS:
5.4
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Oct 20, 2021

CVE-2021-24812 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database