Bulk NoIndex & NoFollow Toolkit <= 2.16 - Reflected Cross-Site Scripting
medium
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...
- CVSS:
- 6.1
- Affected:
- up to 2.16
- Fixed in:
- 2.20
- Disclosed:
- Apr 1, 2025
CVE-2025-31537 on NVD →
Bulk NoIndex & NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 2.20
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in madfishdigital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS. This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.16.
- Affected:
- up to 2.20
- Fixed in:
- 2.20
- Disclosed:
- Apr 1, 2025
CVE-2025-31537 on NVD →
Bulk NoIndex & NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 1.51
unknown
[en] Missing Authorization vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 1.5.
- Affected:
- up to 1.51
- Fixed in:
- 1.51
- Disclosed:
- Dec 13, 2024
CVE-2023-41688 on NVD →
Bulk NoIndex & NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 2.16
unknown
[en] The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- Affected:
- up to 2.16
- Fixed in:
- 2.16
- Disclosed:
- Sep 26, 2024
CVE-2024-8803 on NVD →
Bulk NoIndex & NoFollow Toolkit <= 2.15 - Reflected Cross-Site Scripting
medium
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 2.15
- Fixed in:
- 2.16
- Disclosed:
- Sep 25, 2024
CVE-2024-8803 on NVD →
Bulk NoIndex & NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 2.10
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.01.
- Affected:
- up to 2.10
- Fixed in:
- 2.10
- Disclosed:
- Mar 27, 2024
CVE-2024-29791 on NVD →
Bulk NoIndex & NoFollow Toolkit <= 2.01 - Reflected Cross-Site Scripting via tab, order, and orderby
medium
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab', 'order', and 'orderby’ parameters in versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...
- CVSS:
- 6.1
- Affected:
- up to 2.01
- Fixed in:
- 2.10
- Disclosed:
- Mar 25, 2024
CVE-2024-29791 on NVD →
Bulk NoIndex & NoFollow Toolkit [bulk-noindex-nofollow-toolkit-by-mad-fish] < 1.5
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit plugin <= 1.42 versions.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Oct 18, 2023
CVE-2023-45065 on NVD →
Bulk NoIndex & NoFollow Toolkit <= 1.42 - Reflected Cross-Site Scripting via 's'
medium
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 1.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Oct 3, 2023
CVE-2023-45065 on NVD →
Bulk NoIndex & NoFollow Toolkit <= 1.5 - Missing Authorization
medium
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_page_callback() and update_page_bulk_callback() functions called via AJAX actions in versions up to, and including, 1.5. This makes it possible for authenticated at...
- CVSS:
- 4.3
- Affected:
- up to 1.5
- Fixed in:
- 1.51
- Disclosed:
- Sep 4, 2023
CVE-2023-41688 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database