ClickWhale <= 2.5.0 - Authenticated (Admin+) SQL injection
medium
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection via the export_csv() function in all versions up to, and including, 2.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
- CVSS:
- 4.9
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Sep 19, 2025
CVE-2025-10002 on NVD →
ClickWhale <= 2.4.6 - Missing Authorization
medium
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-leve...
- CVSS:
- 4.3
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- May 7, 2025
CVE-2025-47612 on NVD →
ClickWhale <= 2.4.3 - Cross-Site Request Forgery
medium
The ClickWhale plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request g...
- CVSS:
- 4.3
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Feb 13, 2025
CVE-2025-26963 on NVD →
ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authentica...
- CVSS:
- 6.4
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Jan 28, 2025
CVE-2025-0804 on NVD →
ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Reflected Cross-Site Scripting
medium
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.1. This makes it poss...
- CVSS:
- 6.1
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Jan 10, 2025
CVE-2024-11327 on NVD →
ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Authenticated (Contributor+) SQL Injection
medium
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...
- CVSS:
- 6.5
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Jan 6, 2025
CVE-2024-51715 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database