plugin

Pz Linkcard Vulnerabilities

13 known security issues reported for the Pz Linkcard WordPress plugin. Most recent disclosed Apr 17, 2026.

7 medium

Running Pz Linkcard on your site? Check whether your installed version is affected.

Scan your site free

Pz-LinkCard <= 2.5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

medium

The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,...

CVSS:
6.4
Affected:
up to 2.5.8.1
Fix:
No patched version reported
Disclosed:
Apr 17, 2026

CVE-2026-2434 on NVD →

Pz-LinkCard <= 2.5.6 - Authenticated (Contributor+) Server-Side Request Forgery

medium

The Pz-LinkCard plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used t...

CVSS:
6.4
Affected:
up to 2.5.6
Fixed in:
2.5.7
Disclosed:
Sep 23, 2025

CVE-2025-8594 on NVD →

Pz-LinkCard [pz-linkcard] < 2.5.3

unknown

[en] The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Mar 28, 2024

CVE-2024-0673 on NVD →

Pz-LinkCard [pz-linkcard] < 2.5.3

unknown

[en] The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Mar 28, 2024

CVE-2024-0677 on NVD →

Pz-LinkCard [pz-linkcard] < 2.5.3

unknown

[en] The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Mar 28, 2024

CVE-2024-0672 on NVD →

Pz-LinkCard <= 2.5.2 - Reflected Cross-Site Scripting

medium

The Pz-LinkCard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Mar 7, 2024

CVE-2024-0672 on NVD →

Pz-LinkCard <= 2.5.2 - Sever-Side Request Forgery

medium

The Pz-LinkCard plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.2 via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to make web requests to arbitrary locations originating from the web application and can be...

CVSS:
5
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Mar 7, 2024

CVE-2024-0677 on NVD →

Pz-LinkCard <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbit...

CVSS:
4.4
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Mar 7, 2024

CVE-2024-0673 on NVD →

Pz-LinkCard [pz-linkcard] < 2.5.3

unknown

[en] Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in Poporon Pz-LinkCard plugin <= 2.4.8 versions.

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Nov 22, 2023

CVE-2023-47790 on NVD →

Pz-LinkCard <= 2.5.2 - Cross-Site Request Forgery via page_cacheman

medium

The Pz-LinkCard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the page_cacheman function. This makes it possible for unauthenticated attackers to manage the plugin's caching functionality via a forged req...

CVSS:
5.4
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Nov 14, 2023

CVE-2023-47790 on NVD →

Pz-LinkCard [pz-linkcard] < 2.4.5.3

unknown

[en] The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues

Affected:
up to 2.4.5.3
Fixed in:
2.4.5.3
Disclosed:
Mar 28, 2022

CVE-2021-25012 on NVD →

Pz-LinkCard <= 2.4.5.1 - Reflected Cross-Site Scripting

medium

The Pz-LinkCard plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 2.4.5.1
Fixed in:
2.4.5.2
Disclosed:
Mar 1, 2022

CVE-2021-25012 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database