WP Links Page [wp-links-page] <= 4.9.6 (unfixed + closed)
unknown
[en] The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wit...
- Affected:
- up to 4.9.6
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2025
CVE-2025-10175 on NVD →
WP Links Page <= 4.9.6 - Authenticated (Subscriber+) SQL Injection
medium
The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Sub...
- CVSS:
- 6.5
- Affected:
- up to 4.9.6
- Fixed in:
- 5.0
- Disclosed:
- Oct 10, 2025
CVE-2025-10175 on NVD →
WP Links Page [wp-links-page] <= 4.9.6 (unfixed + closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rico Macchi WP Links Page allows SQL Injection. This issue affects WP Links Page: from n/a through 4.9.6.
- Affected:
- up to 4.9.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2025
CVE-2025-30998 on NVD →
WP Links Page <= 4.9.6 - Authenticated (Subscriber+) SQL Injection
medium
The WP Links Page plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- CVSS:
- 6.5
- Affected:
- up to 4.9.6
- Fixed in:
- 5.0
- Disclosed:
- Jul 22, 2025
CVE-2025-30998 on NVD →
WP Links Page [wp-links-page] < 4.9.6 (closed)
unknown
[en] The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to rege...
- Affected:
- up to 4.9.6
- Fixed in:
- 4.9.6
- Disclosed:
- Jul 13, 2024
CVE-2024-6465 on NVD →
WP Links Page <= 4.9.5 - Missing Authorization to Authenticated (Subscriber+) Limited Image Update
medium
The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to regenerat...
- CVSS:
- 4.3
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.6
- Disclosed:
- Jul 12, 2024
CVE-2024-6465 on NVD →
WP Links Page [wp-links-page] < 4.9.5 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Robert Macchi WP Links Page.This issue affects WP Links Page: from n/a through 4.9.4.
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.5
- Disclosed:
- Nov 18, 2023
CVE-2023-47651 on NVD →
WP Links Page <= 4.9.4 - Cross-Site Request Forgery via wplf_ajax_update_screenshots
medium
The WP Links Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.4. This is due to missing or incorrect nonce validation on the 'wplf_ajax_update_screenshots' function. This makes it possible for unauthenticated attackers to update screenshots via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.5
- Disclosed:
- Nov 7, 2023
CVE-2023-47651 on NVD →
WP Links Page [wp-links-page] < 4.9.4 (closed)
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Robert Macchi WP Links Page plugin <= 4.9.3 versions.
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.4
- Disclosed:
- May 11, 2023
CVE-2023-22720 on NVD →
WP Links Page <= 4.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WP Links Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, and including, 4.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contrib...
- CVSS:
- 6.4
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.2
- Disclosed:
- Apr 19, 2023
CVE-2023-22720 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database