plugin

Clickwhale Vulnerabilities

6 known security issues reported for the Clickwhale WordPress plugin. Most recent disclosed Sep 19, 2025.

6 medium

Running Clickwhale on your site? Check whether your installed version is affected.

Scan your site free

ClickWhale <= 2.5.0 - Authenticated (Admin+) SQL injection

medium

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection via the export_csv() function in all versions up to, and including, 2.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...

CVSS:
4.9
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Sep 19, 2025

CVE-2025-10002 on NVD →

ClickWhale <= 2.4.6 - Missing Authorization

medium

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-leve...

CVSS:
4.3
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
May 7, 2025

CVE-2025-47612 on NVD →

ClickWhale <= 2.4.3 - Cross-Site Request Forgery

medium

The ClickWhale plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request g...

CVSS:
4.3
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Feb 13, 2025

CVE-2025-26963 on NVD →

ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

CVSS:
6.4
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Jan 28, 2025

CVE-2025-0804 on NVD →

ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Reflected Cross-Site Scripting

medium

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.1. This makes it poss...

CVSS:
6.1
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Jan 10, 2025

CVE-2024-11327 on NVD →

ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Authenticated (Contributor+) SQL Injection

medium

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

CVSS:
6.5
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Jan 6, 2025

CVE-2024-51715 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database