plugin

Wp External Links Vulnerabilities

9 known security issues reported for the Wp External Links WordPress plugin. Most recent disclosed Mar 9, 2023.

3 medium

Running Wp External Links on your site? Check whether your installed version is affected.

Scan your site free

External Links &#8211; nofollow, noopener &amp; new window [wp-external-links] < 2.58

unknown

Update the WordPress External Links plugin to the latest available version (at least 2.58). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress External Links Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their...

Affected:
up to 2.58
Fixed in:
2.58
Disclosed:
Mar 9, 2023

External Links <= 2.57 - Cross-Site Request Forgery via action_admin_action_wpel_dismiss_notice

medium

The External Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.7. This is due to missing or incorrect nonce validation on the 'action_admin_action_wpel_dismiss_notice' function. This makes it possible for unauthenticated attackers to dismiss the plugin's admin...

CVSS:
4.3
Affected:
up to 2.57
Fixed in:
2.58
Disclosed:
Mar 8, 2023

External Links &#8211; nofollow, noopener &amp; new window [wp-external-links] < 2.58

unknown

The External Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.7. This is due to missing or incorrect nonce validation on the 'action_admin_action_wpel_dismiss_notice' function. This makes it possible for unauthenticated attackers to dismiss the plugin's admin...

Affected:
up to 2.58
Fixed in:
2.58
Disclosed:
Mar 8, 2023

External Links <= 2.55 - Authenticated (Administrator+) Cross-Site Scripting

medium

The External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.55 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in p...

CVSS:
5.5
Affected:
up to 2.55
Fixed in:
2.56
Disclosed:
Nov 20, 2022

External Links &#8211; nofollow, noopener &amp; new window [wp-external-links] < 2.56

unknown

The External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.55 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in p...

Affected:
up to 2.56
Fixed in:
2.56
Disclosed:
Nov 20, 2022

External Links &#8211; nofollow, noopener &amp; new window [wp-external-links] < 1.81

unknown

This vulnerability allows remote attackers to inject malicious script codes to the application-side of the vulnerable modules. Update the plugin.

Affected:
up to 1.81
Fixed in:
1.81
Disclosed:
Mar 31, 2016

WP External Links < 1.81 - Authenticated Stored Cross-Site Scripting

medium

The WP External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 1.81 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
6.4
Affected:
up to 1.81
Fixed in:
1.81
Disclosed:
Mar 23, 2016

External Links &#8211; nofollow, noopener &amp; new window [wp-external-links] < 1.81

unknown

The WP External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 1.81 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

Affected:
up to 1.81
Fixed in:
1.81
Disclosed:
Mar 23, 2016

External Links &#8211; nofollow, noopener &amp; new window [wp-external-links] < 1.81

unknown

The External Links &ndash; nofollow, noopener &amp; new window WordPress plugin was affected by a Multiple Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.81
Fixed in:
1.81

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database