Pz-LinkCard <= 2.5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
medium
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,...
- CVSS:
- 6.4
- Affected:
- up to 2.5.8.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2026
CVE-2026-2434 on NVD →
Pz-LinkCard <= 2.5.6 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Pz-LinkCard plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used t...
- CVSS:
- 6.4
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.7
- Disclosed:
- Sep 23, 2025
CVE-2025-8594 on NVD →
Pz-LinkCard [pz-linkcard] < 2.5.3
unknown
[en] The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- Mar 28, 2024
CVE-2024-0673 on NVD →
Pz-LinkCard [pz-linkcard] < 2.5.3
unknown
[en] The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- Mar 28, 2024
CVE-2024-0677 on NVD →
Pz-LinkCard [pz-linkcard] < 2.5.3
unknown
[en] The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- Mar 28, 2024
CVE-2024-0672 on NVD →
Pz-LinkCard <= 2.5.2 - Reflected Cross-Site Scripting
medium
The Pz-LinkCard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Mar 7, 2024
CVE-2024-0672 on NVD →
Pz-LinkCard <= 2.5.2 - Sever-Side Request Forgery
medium
The Pz-LinkCard plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.2 via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to make web requests to arbitrary locations originating from the web application and can be...
- CVSS:
- 5
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Mar 7, 2024
CVE-2024-0677 on NVD →
Pz-LinkCard <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbit...
- CVSS:
- 4.4
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Mar 7, 2024
CVE-2024-0673 on NVD →
Pz-LinkCard [pz-linkcard] < 2.5.3
unknown
[en] Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in Poporon Pz-LinkCard plugin <= 2.4.8 versions.
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- Nov 22, 2023
CVE-2023-47790 on NVD →
Pz-LinkCard <= 2.5.2 - Cross-Site Request Forgery via page_cacheman
medium
The Pz-LinkCard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the page_cacheman function. This makes it possible for unauthenticated attackers to manage the plugin's caching functionality via a forged req...
- CVSS:
- 5.4
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Nov 14, 2023
CVE-2023-47790 on NVD →
Pz-LinkCard [pz-linkcard] < 2.4.5.3
unknown
[en] The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues
- Affected:
- up to 2.4.5.3
- Fixed in:
- 2.4.5.3
- Disclosed:
- Mar 28, 2022
CVE-2021-25012 on NVD →
Pz-LinkCard <= 2.4.5.1 - Reflected Cross-Site Scripting
medium
The Pz-LinkCard plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 2.4.5.1
- Fixed in:
- 2.4.5.2
- Disclosed:
- Mar 1, 2022
CVE-2021-25012 on NVD →
Pz-LinkCard [pz-linkcard] < 2.5.7
unknown
- Affected:
- up to 2.5.7
- Fixed in:
- 2.5.7
CVE-2025-8594 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database