Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management <= 152 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 152 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level acces...
- CVSS:
- 6.4
- Affected:
- up to 152
- Fixed in:
- 153
- Disclosed:
- Jul 2, 2026
CVE-2026-57762 on NVD →
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 118
unknown
[en] Missing Authorization vulnerability in Lasso Simple URLs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through 117.
- Affected:
- up to 118
- Fixed in:
- 118
- Disclosed:
- Dec 13, 2024
CVE-2023-40678 on NVD →
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 119
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lasso Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management allows Stored XSS.This issue affects Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management: from n/a throug...
- Affected:
- up to 119
- Fixed in:
- 119
- Disclosed:
- Nov 30, 2023
CVE-2023-40674 on NVD →
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 121
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Lasso Simple URLs plugin <= 120 versions.
- Affected:
- up to 121
- Fixed in:
- 121
- Disclosed:
- Oct 16, 2023
CVE-2023-45606 on NVD →
Simple URLs <= 120 - Cross-Site Request Forgery via Multiple AJAX Actions
medium
The Simple URLs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 120. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to perform unauthorized actions (e.g., delete arbitrary posts, add...
- CVSS:
- 5.4
- Affected:
- up to 120
- Fixed in:
- 121
- Disclosed:
- Oct 11, 2023
CVE-2023-45606 on NVD →
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 118
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions.
- Affected:
- up to 118
- Fixed in:
- 118
- Disclosed:
- Sep 27, 2023
CVE-2023-40667 on NVD →
Simple URLs <= 118 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Simple URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 119 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 118
- Fixed in:
- 119
- Disclosed:
- Aug 21, 2023
CVE-2023-40674 on NVD →
Simple URLs <= 117 - Reflected Cross-Site Scripting via 'post_id'
medium
The Simple URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' parameter in versions up to, and including, 117 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execu...
- CVSS:
- 6.1
- Affected:
- up to 117
- Fixed in:
- 118
- Disclosed:
- Aug 21, 2023
CVE-2023-40667 on NVD →
Simple URLs <= 117 - Missing Authorization via AJAX actions
medium
The Simple URLs plugin for WordPress is vulnerable to unauthorized utilization of AJAX functionality due to a missing capability check on its AJAX handler functions in versions up to, and including, 117. This makes it possible for authenticated attackers, with subscriber-level access and above, to invoke those function...
- CVSS:
- 4.3
- Affected:
- up to 117
- Fixed in:
- 118
- Disclosed:
- Aug 21, 2023
CVE-2023-40678 on NVD →
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 115
unknown
[en] The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.
- Affected:
- up to 115
- Fixed in:
- 115
- Disclosed:
- Feb 13, 2023
CVE-2023-0098 on NVD →
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 115
unknown
[en] The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
- Affected:
- up to 115
- Fixed in:
- 115
- Disclosed:
- Feb 13, 2023
CVE-2023-0099 on NVD →
Simple URLs <= 114 - Authenticated (Subscriber+) SQL Injection
high
The Simple URLs plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in versions up to, and including, 114 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-...
- CVSS:
- 8.8
- Affected:
- up to 114
- Fixed in:
- 115
- Disclosed:
- Jan 17, 2023
CVE-2023-0098 on NVD →
Simple URLs <= 114 - Reflected Cross-Site Scripting
medium
The Simple URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 114 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 114
- Fixed in:
- 115
- Disclosed:
- Jan 17, 2023
CVE-2023-0099 on NVD →
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] <= 117 (unfixed)
unknown
The Simple URLs plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on its AJAX handler functions in versions up to, and including, 117. This makes it possible for unauthenticated attackers to invoke those functions and change plugin behavior and settings provided they can tric...
- Affected:
- up to 117
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database