External Links – nofollow, noopener & new window [wp-external-links] < 2.58
unknown
Update the WordPress External Links plugin to the latest available version (at least 2.58).
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress External Links Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their...
- Affected:
- up to 2.58
- Fixed in:
- 2.58
- Disclosed:
- Mar 9, 2023
External Links <= 2.57 - Cross-Site Request Forgery via action_admin_action_wpel_dismiss_notice
medium
The External Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.7. This is due to missing or incorrect nonce validation on the 'action_admin_action_wpel_dismiss_notice' function. This makes it possible for unauthenticated attackers to dismiss the plugin's admin...
- CVSS:
- 4.3
- Affected:
- up to 2.57
- Fixed in:
- 2.58
- Disclosed:
- Mar 8, 2023
External Links – nofollow, noopener & new window [wp-external-links] < 2.58
unknown
The External Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.7. This is due to missing or incorrect nonce validation on the 'action_admin_action_wpel_dismiss_notice' function. This makes it possible for unauthenticated attackers to dismiss the plugin's admin...
- Affected:
- up to 2.58
- Fixed in:
- 2.58
- Disclosed:
- Mar 8, 2023
External Links <= 2.55 - Authenticated (Administrator+) Cross-Site Scripting
medium
The External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.55 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in p...
- CVSS:
- 5.5
- Affected:
- up to 2.55
- Fixed in:
- 2.56
- Disclosed:
- Nov 20, 2022
External Links – nofollow, noopener & new window [wp-external-links] < 2.56
unknown
The External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.55 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in p...
- Affected:
- up to 2.56
- Fixed in:
- 2.56
- Disclosed:
- Nov 20, 2022
External Links – nofollow, noopener & new window [wp-external-links] < 1.81
unknown
This vulnerability allows remote attackers to inject malicious script codes to the application-side of the vulnerable modules.
Update the plugin.
- Affected:
- up to 1.81
- Fixed in:
- 1.81
- Disclosed:
- Mar 31, 2016
WP External Links < 1.81 - Authenticated Stored Cross-Site Scripting
medium
The WP External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 1.81 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- CVSS:
- 6.4
- Affected:
- up to 1.81
- Fixed in:
- 1.81
- Disclosed:
- Mar 23, 2016
External Links – nofollow, noopener & new window [wp-external-links] < 1.81
unknown
The WP External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 1.81 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- Affected:
- up to 1.81
- Fixed in:
- 1.81
- Disclosed:
- Mar 23, 2016
External Links – nofollow, noopener & new window [wp-external-links] < 1.81
unknown
The External Links – nofollow, noopener & new window WordPress plugin was affected by a Multiple Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.81
- Fixed in:
- 1.81
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database