Extension WordPress
Vulnérabilités URL Shortify – Simple and Easy URL Shortener
Cette page rassemble les failles publiées pour URL Shortify – Simple and Easy URL Shortener, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de URL Shortify – Simple and Easy URL Shortener
12 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.10.4
1.10.5.1
30/04/2026
URL Shortify <= 1.12.3 – Authenticated (Author+) Server-Side Request Forgery
The URL Shortify – Simple and Easy URL Shortener plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.12.3. This makes it possible for authenticated attackers, with Author-level access and above,…
*-1.12.3
1.12.4
19/02/2026
URL Shortify <= 1.12.1 – Unauthenticated Open Redirect via 'redirect_to' Parameter
The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated…
*-1.12.1
1.12.2
17/02/2026
URL Shortify <= 1.11.3 – Reflected Cross-Site Scripting
The URL Shortify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.11.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.11.3
1.11.4
24/11/2025
URL Shortify <= 1.11.2 – Reflected Cross-Site Scripting
The URL Shortify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.11.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.11.2
1.11.3
24/11/2025
URL Shortify <= 1.10.5.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The URL Shortify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.10.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
*-1.10.5.1
1.10.6
04/04/2025
URL Shortify <= 1.7.9 – Authenticated (Admin+) Stored Cross-Site Scripting
The URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.9 due to insufficient input sanitization…
*-1.7.9
1.7.9.1
16/11/2023
URL Shortify <= 1.7.5 – Unauthenticated Stored Cross-Site Scripting via Referrer Header
The URL Shortify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the referrer header in versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-1.7.5
1.7.6
21/08/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
1.0.1-1.7.2
1.7.3
18/07/2023
URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress <= 1.6.5 – Authenticated (Admin+) Stored Cross-Site Scripting
The URL Shortify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping on the "Link Prefix" setting. This makes it…
[*, 1.7.0)
1.7.0
19/06/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.5.11)
1.5.11
04/03/2022
URL Shortify <= 1.5.0 – Cross-Site Request Forgery
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.
*-1.5.0
1.5.1
28/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.