Extension WordPress
Vulnérabilités ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages
Cette page rassemble les failles publiées pour ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages
6 fiches
ClickWhale <= 2.5.0 – Authenticated (Admin+) SQL injection
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection via the export_csv() function in all versions up to, and including, 2.5.0 due to…
*-2.5.0
2.5.1
19/09/2025
ClickWhale <= 2.4.6 – Missing Authorization
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to,…
*-2.4.6
2.4.7
07/05/2025
ClickWhale <= 2.4.3 – Cross-Site Request Forgery
The ClickWhale plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attackers…
*-2.4.3
2.4.4
13/02/2025
ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to…
*-2.4.1
2.4.2
28/01/2025
ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 – Reflected Cross-Site Scripting
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the…
*-2.4.1
2.4.2
10/01/2025
ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 – Authenticated (Contributor+) SQL Injection
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.4.1 due to insufficient escaping on the…
*-2.4.1
2.4.2
06/01/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.