plugin

Simple Urls Vulnerabilities

14 known security issues reported for the Simple Urls WordPress plugin. Most recent disclosed Jul 2, 2026.

1 high 6 medium

Running Simple Urls on your site? Check whether your installed version is affected.

Scan your site free

Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management <= 152 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 152 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level acces...

CVSS:
6.4
Affected:
up to 152
Fixed in:
153
Disclosed:
Jul 2, 2026

CVE-2026-57762 on NVD →

Simple URLs &#8211; Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 118

unknown

[en] Missing Authorization vulnerability in Lasso Simple URLs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through 117.

Affected:
up to 118
Fixed in:
118
Disclosed:
Dec 13, 2024

CVE-2023-40678 on NVD →

Simple URLs &#8211; Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 119

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lasso Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management allows Stored XSS.This issue affects Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management: from n/a throug...

Affected:
up to 119
Fixed in:
119
Disclosed:
Nov 30, 2023

CVE-2023-40674 on NVD →

Simple URLs &#8211; Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 121

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Lasso Simple URLs plugin <= 120 versions.

Affected:
up to 121
Fixed in:
121
Disclosed:
Oct 16, 2023

CVE-2023-45606 on NVD →

Simple URLs <= 120 - Cross-Site Request Forgery via Multiple AJAX Actions

medium

The Simple URLs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 120. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to perform unauthorized actions (e.g., delete arbitrary posts, add...

CVSS:
5.4
Affected:
up to 120
Fixed in:
121
Disclosed:
Oct 11, 2023

CVE-2023-45606 on NVD →

Simple URLs &#8211; Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 118

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions.

Affected:
up to 118
Fixed in:
118
Disclosed:
Sep 27, 2023

CVE-2023-40667 on NVD →

Simple URLs <= 118 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Simple URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 119 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 118
Fixed in:
119
Disclosed:
Aug 21, 2023

CVE-2023-40674 on NVD →

Simple URLs <= 117 - Reflected Cross-Site Scripting via 'post_id'

medium

The Simple URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' parameter in versions up to, and including, 117 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execu...

CVSS:
6.1
Affected:
up to 117
Fixed in:
118
Disclosed:
Aug 21, 2023

CVE-2023-40667 on NVD →

Simple URLs <= 117 - Missing Authorization via AJAX actions

medium

The Simple URLs plugin for WordPress is vulnerable to unauthorized utilization of AJAX functionality due to a missing capability check on its AJAX handler functions in versions up to, and including, 117. This makes it possible for authenticated attackers, with subscriber-level access and above, to invoke those function...

CVSS:
4.3
Affected:
up to 117
Fixed in:
118
Disclosed:
Aug 21, 2023

CVE-2023-40678 on NVD →

Simple URLs &#8211; Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 115

unknown

[en] The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

Affected:
up to 115
Fixed in:
115
Disclosed:
Feb 13, 2023

CVE-2023-0098 on NVD →

Simple URLs &#8211; Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] < 115

unknown

[en] The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Affected:
up to 115
Fixed in:
115
Disclosed:
Feb 13, 2023

CVE-2023-0099 on NVD →

Simple URLs <= 114 - Authenticated (Subscriber+) SQL Injection

high

The Simple URLs plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in versions up to, and including, 114 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-...

CVSS:
8.8
Affected:
up to 114
Fixed in:
115
Disclosed:
Jan 17, 2023

CVE-2023-0098 on NVD →

Simple URLs <= 114 - Reflected Cross-Site Scripting

medium

The Simple URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 114 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 114
Fixed in:
115
Disclosed:
Jan 17, 2023

CVE-2023-0099 on NVD →

Simple URLs &#8211; Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] <= 117 (unfixed)

unknown

The Simple URLs plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on its AJAX handler functions in versions up to, and including, 117. This makes it possible for unauthenticated attackers to invoke those functions and change plugin behavior and settings provided they can tric...

Affected:
up to 117
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database