plugin

Easy Broken Link Checker Vulnerabilities

8 known security issues reported for the Easy Broken Link Checker WordPress plugin. Most recent disclosed Mar 6, 2025.

4 medium

Running Easy Broken Link Checker on your site? Check whether your installed version is affected.

Scan your site free

URL Shortener | Conversion Tracking | AB Testing | WooCommerce [easy-broken-link-checker] <= 9.0.2 (unfixed + closed)

unknown

[en] The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Affected:
up to 9.0.2
Fix:
No patched version reported
Disclosed:
Mar 6, 2025

CVE-2024-13868 on NVD →

URL Shortener | Conversion Tracking | AB Testing | WooCommerce <= 9.0.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin...

CVSS:
4.4
Affected:
up to 9.0.2
Fix:
No patched version reported
Disclosed:
Feb 16, 2025

CVE-2025-1363 on NVD →

URL Shortener | Conversion Tracking | AB Testing | WooCommerce <= 9.0.2 - Cross-Site Request Forgery

medium

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.2. This is due to missing or incorrect nonce validation on the 'eblc_check_options' page. This makes it possible for unauthenticated attackers t...

CVSS:
4.3
Affected:
up to 9.0.2
Fix:
No patched version reported
Disclosed:
Feb 16, 2025

CVE-2025-1362 on NVD →

URL Shortener | Conversion Tracking | AB Testing | WooCommerce [easy-broken-link-checker] <= 9.0.2 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tahminajannat URL Shortener | Conversion Tracking | AB Testing | WooCommerce allows Reflected XSS. This issue affects URL Shortener | Conversion Tracking | AB Testing | WooCommerce: from n/a through 9.0.2.

Affected:
up to 9.0.2
Fix:
No patched version reported
Disclosed:
Feb 14, 2025

CVE-2025-23789 on NVD →

URL Shortener | Conversion Tracking | AB Testing | WooCommerce <= 9.0.2 - Reflected Cross-Site Scripting

medium

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eblc_tab' parameter in all versions up to, and including, 9.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...

CVSS:
6.1
Affected:
up to 9.0.2
Fix:
No patched version reported
Disclosed:
Feb 13, 2025

CVE-2024-13868 on NVD →

URL Shortener | Conversion Tracking | AB Testing | WooCommerce <= 9.0.2 - Reflected Cross-Site Scripting

medium

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 9.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 9.0.2
Fix:
No patched version reported
Disclosed:
Jan 16, 2025

CVE-2025-23789 on NVD →

URL Shortener | Conversion Tracking | AB Testing | WooCommerce [easy-broken-link-checker] <= 9.0.2 (unfixed + closed)

unknown
Affected:
up to 9.0.2
Fix:
No patched version reported

CVE-2025-1363 on NVD →

URL Shortener | Conversion Tracking | AB Testing | WooCommerce [easy-broken-link-checker] <= 9.0.2 (unfixed + closed)

unknown
Affected:
up to 9.0.2
Fix:
No patched version reported

CVE-2025-1362 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database