plugin

Bulk Noindex Nofollow Toolkit By Mad Fish Vulnerabilities

10 known security issues reported for the Bulk Noindex Nofollow Toolkit By Mad Fish WordPress plugin. Most recent disclosed Apr 1, 2025.

5 medium

Running Bulk Noindex Nofollow Toolkit By Mad Fish on your site? Check whether your installed version is affected.

Scan your site free

Bulk NoIndex & NoFollow Toolkit <= 2.16 - Reflected Cross-Site Scripting

medium

The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...

CVSS:
6.1
Affected:
up to 2.16
Fixed in:
2.20
Disclosed:
Apr 1, 2025

CVE-2025-31537 on NVD →

Bulk NoIndex &amp; NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 2.20

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in madfishdigital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS. This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.16.

Affected:
up to 2.20
Fixed in:
2.20
Disclosed:
Apr 1, 2025

CVE-2025-31537 on NVD →

Bulk NoIndex &amp; NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 1.51

unknown

[en] Missing Authorization vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 1.5.

Affected:
up to 1.51
Fixed in:
1.51
Disclosed:
Dec 13, 2024

CVE-2023-41688 on NVD →

Bulk NoIndex &amp; NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 2.16

unknown

[en] The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

Affected:
up to 2.16
Fixed in:
2.16
Disclosed:
Sep 26, 2024

CVE-2024-8803 on NVD →

Bulk NoIndex & NoFollow Toolkit <= 2.15 - Reflected Cross-Site Scripting

medium

The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 2.15
Fixed in:
2.16
Disclosed:
Sep 25, 2024

CVE-2024-8803 on NVD →

Bulk NoIndex &amp; NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 2.10

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.01.

Affected:
up to 2.10
Fixed in:
2.10
Disclosed:
Mar 27, 2024

CVE-2024-29791 on NVD →

Bulk NoIndex & NoFollow Toolkit <= 2.01 - Reflected Cross-Site Scripting via tab, order, and orderby

medium

The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab', 'order', and 'orderby’ parameters in versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...

CVSS:
6.1
Affected:
up to 2.01
Fixed in:
2.10
Disclosed:
Mar 25, 2024

CVE-2024-29791 on NVD →

Bulk NoIndex &amp; NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 1.5

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit plugin <= 1.42 versions.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Oct 18, 2023

CVE-2023-45065 on NVD →

Bulk NoIndex & NoFollow Toolkit <= 1.42 - Reflected Cross-Site Scripting via 's'

medium

The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 1.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Oct 3, 2023

CVE-2023-45065 on NVD →

Bulk NoIndex & NoFollow Toolkit <= 1.5 - Missing Authorization

medium

The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_page_callback() and update_page_bulk_callback() functions called via AJAX actions in versions up to, and including, 1.5. This makes it possible for authenticated at...

CVSS:
4.3
Affected:
up to 1.5
Fixed in:
1.51
Disclosed:
Sep 4, 2023

CVE-2023-41688 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database